Skip to content
Commit Detail

Commit ddd54a6

Author
James M Snell <jsnell@cloudflare.com> 2026-03-16 20:00:43 -0700
Parents
e7f150d
Tree
0f50eab
Validate DH public keys proactively in setPublicKey and computeSecret

`DiffieHellman::setPublicKey()` accepted arbitrary byte arrays without
validation, allowing keys of 0, 1, or values >= p that would cause
`computeSecret()` to produce predictable or weak shared secrets.
`computeSecret()` only called `DH_check_pub_key` on the error path
after `DH_compute_key` had already failed.

Add `DH_check_pub_key` validation in both `setPublicKey()` (rejects
invalid keys at the point they're set) and `computeSecret()` (rejects
invalid peer keys before computing the shared secret, not after).
This catches small subgroup attacks and out-of-range keys with clear
error messages.

Files changed

2 files changed~2 modified