Skip to content

Reject nonempty DigestAlgorithm NULL parameters - #1157

Open
itsalexfer wants to merge 2 commits into
digitalbazaar:mainfrom
itsalexfer:fix/reject-nonempty-digest-null
Open

itsalexfer wants to merge 2 commits into
digitalbazaar:mainfrom
itsalexfer:fix/reject-nonempty-digest-null

Conversation

@itsalexfer

Copy link
Copy Markdown

Builds on #1152, with credit to @Krysthyan for its nested DigestAlgorithm element-count fix and @geo-chen for the original report.

This supplement also rejects primitive ASN.1 NULL parameters containing bytes, which must have empty contents. The new synthetic private-key fixtures demonstrate malformed-encoding acceptance, not forgery without a private key. Compatibility tests retain absent and empty NULL parameters, legacy BER verification, PSS, NONE, and native-generated signatures.

Tests: Node 24.14.1 with pinned upstream Mocha 5.2.0: 837 passing, 4 pending; RSA subset: 109 passing, 4 pending. Focused prior-code checks: 8 passing/1 expected failure; patched: 9 passing. Existing lint errors remain; the borrowed regression adds one unused-variable warning.

AI disclosure: Supplemental tests were generated by an AI agent using GPT-6 Astra (Max reasoning). The NULL guard already existed in our local Lerix mitigation. We are contributing it to support eventual adoption of an official release.

Cristhian Hernandez and others added 2 commits October 4, 2026 09:01
Require DigestAlgorithm SEQUENCE element count (OID + optional NULL) so
asn1.validate cannot ignore interior padding that bypasses CVE-2026-33894.

Co-authored-by: Cursor <cursoragent@cursor.com>
Supplement the nested element-count fix with strict NULL contents validation and compatibility tests.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant