address RUSTSEC-2026-0104 (#35767)

This commit is contained in:
Kyle Den Hartog
2026-04-22 06:50:20 -07:00
committed by GitHub
parent 6a3e634a7d
commit bf96c459c6
9 changed files with 69 additions and 20 deletions
+2 -2
View File
@@ -2230,9 +2230,9 @@ dependencies = [ "web-time", "zeroize",]
[[package]]
name = "rustls-webpki"
version = "0.103.12"
version = "0.103.13"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8279bb85272c9f10811ae6a6c547ff594d6a7f3c6c6b02ee9726d1d0dcfcdd06"
checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e"
dependencies = [ "ring", "rustls-pki-types", "untrusted",]
[[package]]
+1 -1
View File
@@ -1 +1 @@
{"files": {".cargo_vcs_info.json": "1706044141e1137c1c13af54c619f0d6684d907374aae5c0c3ee16356dfdd0d4", "Cargo.lock": "79d691c02efaf7a6d4d95ad84e9aab515d7ebb7028dadace899f6471e5c6d066", "Cargo.toml": "d3d535a11ea9f9efa64c7a54444c72516a108b07eca25848823fb43f7aa8d548", "Cargo.toml.orig": "88ccc976fd5add8e279f058b635a84e1c6fdaa8c7f580086880b5ba399eff086", "LICENSE": "5b698ca13897be3afdb7174256fa1574f8c6892b8bea1a66dd6469d3fe27885a", "README.md": "084c37ee4b35887c813373cb98f3712e20d42e238cd16b59bd90dd8ae870dbf2", "src/alg_tests.rs": "aa05065896cebe413d8d03a57842e5c34d201f2b914d2ff16f351230d810f19f", "src/aws_lc_rs_algs.rs": "f220ede4189835dbeb3d63d5f3629c59fb3d51651b19a3835eec73381c5f558d", "src/cert.rs": "1a4da3c745a72f61e8e95f222fc5847cb4779a4de524f4d6d09ae1d25b27c001", "src/crl/mod.rs": "6b59ca00ed53c0883ce13a36880636a1c41053013c9ced732859b0c1b3d60ff3", "src/crl/types.rs": "fe04d994410819d88e5161cd58707574f92025e115d79d8a633711d627da008f", "src/data/alg-rsa-pkcs1-sha256-absent-params.der": "269462d02de5597c547cc473cefb4471ee93d836c75d272a0e5a36863e96d228", "src/data/alg-rsa-pkcs1-sha384-absent-params.der": "dc7e012a12d034dd581de85ad49913a020df7c8a684213f03629c1fd53dcf14f", "src/data/alg-rsa-pkcs1-sha512-absent-params.der": "1c9021c531e93720d2539bd989fbd9f6ce34d24aa0b694c376a87c0a1ba9dd29", "src/der.rs": "73e7db1a260b9c48d247dad0ea9211cd046cede29363a8c54cbe4dc025370ef4", "src/end_entity.rs": "dcd6176df075627bbd38881bb1b729462721ecb53e7968d56b116a8532043c42", "src/error.rs": "6d79c7ec3b9063e156670c4db7155eb04cdf67b82ea384bc33c1f2c7109a32fc", "src/lib.rs": "4fc2b9e67c3b68fabf65d4aadda9ed3fea39e3af61e41ad40fe36bdd1cae52dd", "src/ring_algs.rs": "f6b17aa2e26442b6c940c5bf4b8e431a9e74152ba8b0573a3f74b99a73ba5412", "src/rpk_entity.rs": "29a59f4c5123fca851ff6b8a6a7f3120f2890df90d3169367f611dc05f31ed3b", "src/signed_data.rs": "9edbc160fd6ec158bbcc67e408c2bc09078142c4feee3ce6e8dae6b7da806fe0", "src/subject_name/dns_name.rs": "c5989e0e46973d8d6a3e94608aad7964089f25599c1f326a6ac30f85204c8328", "src/subject_name/ip_address.rs": "e76e24bfb15d367732fccd4cc0ebae3bb3970d4a209b7c30a67263ab14200185", "src/subject_name/mod.rs": "665c7e532737809a52304095ed04540a0617d5a65c66d5553071d1bd907c9ffe", "src/time.rs": "e92721be14ac2f99b4a9a28125947307bbb1f87136b64e2b51ea07644fafa7a6", "src/trust_anchor.rs": "5a4a54b4525b710bfadb4c35f041700e965b51631d4b9b8d9842c157f057b5b1", "src/verify_cert.rs": "235986cb11713f256caea24f29fece0c767896bf4a6de35764205cf1adb5fed9", "src/x509.rs": "3c12557b2430268e0155094883e119414bd2e94776d757bfe5c38a3c3490958e"}, "package": "8279bb85272c9f10811ae6a6c547ff594d6a7f3c6c6b02ee9726d1d0dcfcdd06"}
{"files": {".cargo_vcs_info.json": "27fe0c3d4d72dcbaf59fa2a7f9e34b1e056435f2d67591219b294a613e272bc0", "Cargo.lock": "c821765eec9b1c6d6f55b7f9ada070f6be7504a82af2d1ee363fc38c3b04c2e1", "Cargo.toml": "a9b2f60ecbca2b9e33449899b15e344c2003664c5901bec9b8ada33722c18285", "Cargo.toml.orig": "35b44a3ba7e46cd4b05d678bd52de7698bd20846e019ca901b648065f0961474", "LICENSE": "5b698ca13897be3afdb7174256fa1574f8c6892b8bea1a66dd6469d3fe27885a", "README.md": "084c37ee4b35887c813373cb98f3712e20d42e238cd16b59bd90dd8ae870dbf2", "src/alg_tests.rs": "aa05065896cebe413d8d03a57842e5c34d201f2b914d2ff16f351230d810f19f", "src/aws_lc_rs_algs.rs": "f220ede4189835dbeb3d63d5f3629c59fb3d51651b19a3835eec73381c5f558d", "src/cert.rs": "1a4da3c745a72f61e8e95f222fc5847cb4779a4de524f4d6d09ae1d25b27c001", "src/crl/mod.rs": "6b59ca00ed53c0883ce13a36880636a1c41053013c9ced732859b0c1b3d60ff3", "src/crl/types.rs": "ff0a08f92bcae303b4148cb40f267a2dbc99732afd52c70c261a8ecd2d6070ba", "src/data/alg-rsa-pkcs1-sha256-absent-params.der": "269462d02de5597c547cc473cefb4471ee93d836c75d272a0e5a36863e96d228", "src/data/alg-rsa-pkcs1-sha384-absent-params.der": "dc7e012a12d034dd581de85ad49913a020df7c8a684213f03629c1fd53dcf14f", "src/data/alg-rsa-pkcs1-sha512-absent-params.der": "1c9021c531e93720d2539bd989fbd9f6ce34d24aa0b694c376a87c0a1ba9dd29", "src/der.rs": "ed693c0410cb8e89e586de76682841156dc3825f9a4181ac7f425232d8640da0", "src/end_entity.rs": "dcd6176df075627bbd38881bb1b729462721ecb53e7968d56b116a8532043c42", "src/error.rs": "6d79c7ec3b9063e156670c4db7155eb04cdf67b82ea384bc33c1f2c7109a32fc", "src/lib.rs": "4fc2b9e67c3b68fabf65d4aadda9ed3fea39e3af61e41ad40fe36bdd1cae52dd", "src/ring_algs.rs": "f6b17aa2e26442b6c940c5bf4b8e431a9e74152ba8b0573a3f74b99a73ba5412", "src/rpk_entity.rs": "29a59f4c5123fca851ff6b8a6a7f3120f2890df90d3169367f611dc05f31ed3b", "src/signed_data.rs": "9edbc160fd6ec158bbcc67e408c2bc09078142c4feee3ce6e8dae6b7da806fe0", "src/subject_name/dns_name.rs": "c5989e0e46973d8d6a3e94608aad7964089f25599c1f326a6ac30f85204c8328", "src/subject_name/ip_address.rs": "e76e24bfb15d367732fccd4cc0ebae3bb3970d4a209b7c30a67263ab14200185", "src/subject_name/mod.rs": "4415187af1bb98ac076d5a0e8b5f224f173bae006629bd35bb465cd0f11e7130", "src/time.rs": "e92721be14ac2f99b4a9a28125947307bbb1f87136b64e2b51ea07644fafa7a6", "src/trust_anchor.rs": "5a4a54b4525b710bfadb4c35f041700e965b51631d4b9b8d9842c157f057b5b1", "src/verify_cert.rs": "235986cb11713f256caea24f29fece0c767896bf4a6de35764205cf1adb5fed9", "src/x509.rs": "3c12557b2430268e0155094883e119414bd2e94776d757bfe5c38a3c3490958e"}, "package": "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e"}
+1 -1
View File
@@ -1,6 +1,6 @@
{
"git": {
"sha1": "27131d476e2b68a537e629d6d012bef8dad6efd3"
"sha1": "2879b2ce7a476181ac3050f73fe0835f04728e86"
},
"path_in_vcs": ""
}
+1 -1
View File
@@ -533,7 +533,7 @@ dependencies = [
[[package]]
name = "rustls-webpki"
version = "0.103.12"
version = "0.103.13"
dependencies = [
"aws-lc-rs",
"base64",
+1 -1
View File
@@ -13,7 +13,7 @@
edition = "2021"
rust-version = "1.71"
name = "rustls-webpki"
version = "0.103.12"
version = "0.103.13"
build = false
include = [
"Cargo.toml",
+1 -1
View File
@@ -21,7 +21,7 @@ license = "ISC"
name = "rustls-webpki"
readme = "README.md"
repository = "https://github.com/rustls/webpki"
version = "0.103.12"
version = "0.103.13"
include = [
"Cargo.toml",
+18
View File
@@ -1270,4 +1270,22 @@ mod tests {
include_bytes!("../../tests/client_auth_revocation/ee_revoked_crl_ku_ee_depth.crl.der");
assert!(OwnedCertRevocationList::from_der(crl).is_ok())
}
#[test]
fn test_crl_issuing_distribution_point_illegal_bit_string() {
let crl = &[
0x30, 0x65, 0x30, 0x50, 0x02, 0x01, 0x01, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48,
0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30, 0x0c, 0x31, 0x0a, 0x30, 0x08,
0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x01, 0x41, 0x17, 0x0d, 0x32, 0x30, 0x30, 0x31,
0x30, 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x17, 0x0d, 0x32, 0x31, 0x30,
0x31, 0x30, 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0xa0, 0x10, 0x30, 0x0e,
0x30, 0x0c, 0x06, 0x03, 0x55, 0x1d, 0x1c, 0x04, 0x05, 0x30, 0x03, 0x83, 0x01, 0x00,
0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05,
0x00, 0x03, 0x02, 0x00, 0x00,
];
assert_eq!(
BorrowedCertRevocationList::from_der(crl).err(),
Some(Error::UnsupportedRevocationReasonsPartitioning)
);
}
}
+37 -12
View File
@@ -379,20 +379,19 @@ pub(crate) fn bit_string_flags(input: untrusted::Input<'_>) -> Result<BitStringF
let padding_bits = bit_string.read_byte().map_err(|_| Error::BadDer)?;
let raw_bits = bit_string.read_bytes_to_end().as_slice_less_safe();
// It's illegal to have more than 7 bits of padding. Similarly, if the raw bitflags
// are empty there should be no padding.
if padding_bits > 7 || (raw_bits.is_empty() && padding_bits != 0) {
return Err(Error::BadDer);
}
match (padding_bits, raw_bits.last()) {
// It's illegal to have more than 7 bits of padding.
(8.., _) => Err(Error::BadDer),
// If there are padding bits then the last bit of the last raw byte must be 0 or the
// distinguished encoding rules are not being followed.
let last_byte = raw_bits[raw_bits.len() - 1];
let padding_mask = (1 << padding_bits) - 1;
// If the raw bitflags are empty there should be no padding.
(0, None) => Ok(BitStringFlags { raw_bits }),
(_, None) => Err(Error::BadDer),
match padding_bits > 0 && (last_byte & padding_mask) != 0 {
true => Err(Error::BadDer),
false => Ok(BitStringFlags { raw_bits }),
// If there are padding bits then the last bit of the last raw byte must be 0 or the
// distinguished encoding rules are not being followed.
(1..=7, Some(last)) if last & ((1 << padding_bits) - 1) != 0 => Err(Error::BadDer),
(_, Some(_)) => Ok(BitStringFlags { raw_bits }),
}
})
}
@@ -766,6 +765,14 @@ mod tests {
bit_string_flags(bad_padding_example),
Err(Error::BadDer)
));
// invalid padding for empty set
for pad in 1..=255 {
assert_eq!(
bit_string_flags(untrusted::Input::from(&[pad])).err(),
Some(Error::BadDer)
);
}
}
#[test]
@@ -792,6 +799,24 @@ mod tests {
assert!(!res.bit_set(256));
}
#[test]
fn empty_bit_string_flags() {
let bs = super::bit_string_flags(untrusted::Input::from(&[0x00])).unwrap();
// all bits are unset
for b in 0..256 {
assert!(!bs.bit_set(b));
}
}
#[test]
fn mispadded_bit_string_flags() {
assert_eq!(
super::bit_string_flags(untrusted::Input::from(&[0x04, 0xff])).err(),
Some(super::Error::BadDer)
);
}
#[test]
fn test_small_nonnegative_integer() {
use super::{Error, FromDer, Tag};
+7 -1
View File
@@ -164,10 +164,16 @@ fn check_presented_id_conforms_to_constraints(
(GeneralName::IpAddress(_), _) => continue,
// We currently don't support URI constraints -- fail closed for now.
//
// Rejection is achieved by not matching any PermittedSubtrees, and matching all
// ExcludedSubtrees.
(
GeneralName::UniformResourceIdentifier(_),
GeneralName::UniformResourceIdentifier(_),
) => Ok(false),
) => Ok(match subtrees {
Subtrees::Permitted => false,
Subtrees::Excluded => true,
}),
(GeneralName::UniformResourceIdentifier(_), _) => continue,
// RFC 4280 says "If a name constraints extension that is marked as