Skip to content

fix(migtd): bound untrusted input sizes before allocation - #1012

Draft
MichalTarnacki wants to merge 1 commit into
intel:mainfrom
MichalTarnacki:fix/impl-bugs-migtd-2
Draft

fix(migtd): bound untrusted input sizes before allocation#1012
MichalTarnacki wants to merge 1 commit into
intel:mainfrom
MichalTarnacki:fix/impl-bugs-migtd-2

Conversation

@MichalTarnacki

Copy link
Copy Markdown
Contributor

Reject pre-session payloads larger than 64 KiB before allocating the receive buffer, so an untrusted peer cannot request an excessive allocation.

Bound peer certificates by the TLS input buffer size before DER parsing. The previous 8 KiB limit was arbitrary and smaller than a valid MigTD certificate, which embeds a TDX quote and the event log. Apply the bound in every verification path instead of the legacy one only, and export TLS_BUFFER_SIZE so the limit tracks the buffer it derives from.

Assisted-by: GitHub Copilot:GPT-5.6 Sol
Assisted-by: GitHub Copilot:Claude Opus 5

Reject pre-session payloads larger than 64 KiB before allocating the
receive buffer, so an untrusted peer cannot request an excessive
allocation.

Bound peer certificates by the TLS input buffer size before DER
parsing. The previous 8 KiB limit was arbitrary and smaller than a
valid MigTD certificate, which embeds a TDX quote and the event log.
Apply the bound in every verification path instead of the legacy one
only, and export TLS_BUFFER_SIZE so the limit tracks the buffer it
derives from.

Signed-off-by: Michal Tarnacki <michal.tarnacki@intel.com>
Assisted-by: GitHub Copilot:GPT-5.6 Sol
Assisted-by: GitHub Copilot:Claude Opus 5
@MichalTarnacki
MichalTarnacki marked this pull request as draft August 26, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants