Merge pull request #9418 from SparkiDev/tls13_ks_dup_check_fix

TLS 1.3 duplicate KeyShare entry fix
This commit is contained in:
David Garske
2025-11-12 16:09:11 -08:00
committed by GitHub

View File

@@ -9830,7 +9830,7 @@ static int TLSX_KeyShareEntry_Parse(const WOLFSSL* ssl, const byte* input,
return BUFFER_ERROR;
if (seenGroups != NULL) {
if (*seenGroupsCnt == MAX_KEYSHARE_NAMED_GROUPS) {
if (*seenGroupsCnt >= MAX_KEYSHARE_NAMED_GROUPS) {
return BAD_KEY_SHARE_DATA;
}
for (i = 0; i < *seenGroupsCnt; i++) {