Skip to content
Commit Detail

Commit 876efe8

Author
James M Snell <jsnell@cloudflare.com> 2026-03-16 19:04:55 -0700
Parents
801d004
Tree
4d31916
Fix BIGNUM memory safety in RSA/DH key import

`toBignumUnowned()` calls `BN_bin2bn()` which can return nullptr on
allocation failure. The raw pointer was passed directly to BoringSSL
ownership-transfer functions (`RSA_set0_key`, `DH_set0_key`, etc.)
without null checking, leading to silent no-ops or undefined behavior.

Additionally, when multiple `toBignumUnowned()` calls appeared in
sequence (RSA JWK import with 8 parameters), a throw from any
allocation or base64 decode would leak all previously-allocated raw
BIGNUM pointers that hadn't yet been transferred to the RSA key.

Changes:
- `toBignumUnowned()` now throws `DOMOperationError` on null return
- Added `toBignumOwned()` returning `UniqueBignum` (`std::unique_ptr`
  with `BN_clear_free`) for RAII-safe allocation
- Converted all RSA JWK import sites (`Rsa::fromJwk`, `rsaJwkReader`)
  to use `toBignumOwned` — BIGNUM is freed on any throw, ownership
  transferred via `.release()` only after successful `RSA_set0_*` call
- Converted DH `setPrivateKey`/`setPublicKey` to use `toBignumOwned`
  with `.get()` then `.release()` after successful `DH_set0_key`

Files changed