Merge pull request #8625 from davidhorstmann-arm/fix-uninit-mpi-test-2.28

[Backport 2.28] Fix possible free of uninitialized MPI
This commit is contained in:
Dave Rodgman 2023-12-13 11:19:21 +00:00 committed by GitHub
commit 4966eb8ce8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -435,10 +435,11 @@ void x509_set_serial_check()
mbedtls_mpi serial_mpi;
uint8_t invalid_serial[MBEDTLS_X509_RFC5280_MAX_SERIAL_LEN + 1];
mbedtls_mpi_init(&serial_mpi);
USE_PSA_INIT();
memset(invalid_serial, 0x01, sizeof(invalid_serial));
mbedtls_mpi_init(&serial_mpi);
TEST_EQUAL(mbedtls_mpi_read_binary(&serial_mpi, invalid_serial,
sizeof(invalid_serial)), 0);
TEST_EQUAL(mbedtls_x509write_crt_set_serial(&ctx, &serial_mpi),