Skip to content

fix: zeroize EC private-key DER before free - #269

Merged
aidankeefe2022 merged 1 commit into
wolfSSL:mainfrom
MarkAtwood:fix/ecparam-forcezero-der-privkey
Oct 1, 2026
Merged

aidankeefe2022 merged 1 commit into
wolfSSL:mainfrom
MarkAtwood:fix/ecparam-forcezero-der-privkey

Conversation

@MarkAtwood

@MarkAtwood MarkAtwood commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Bug

In wolfCLU_ecparam (src/ecparam/clu_ecparam.c), the ecparam -genkey ... -outform der path serializes the EC private key into a der buffer via wolfSSL_i2d_ECPrivateKey, writes it out, then frees it with XFREE without zeroizing. The freed heap buffer holds live private-key material.

Fix

ForceZero the buffer before XFREE, matching wolfCLU's own established convention for DER private-key buffers (src/pkey/clu_pkey.c:340, src/pkey/clu_rsa.c:273, src/ocsp/clu_ocsp.c:893). The ecparam genkey DER path was the sole outlier. The derSz > 0 guard is defensive since wolfCLU_ForceZero(void*, unsigned int) casts the length.

How verified

Built against a full --enable-all wolfSSL install: make -j8 recompiles clu_ecparam.o and relinks the wolfssl binary, exit 0. Runtime repro confirmed the pre-fix buffer held a valid 256-bit EC private key (decoded independently with OpenSSL).

Reported by static analysis (Fenrir finding 667, missing_forcezero).

[fenrir-sweep:held]

Copilot AI review requested due to automatic review settings July 9, 2026 23:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot couldn't run its full agentic review because no GitHub Actions runner was available. Make sure your repository has a runner available to run Copilot's review, or add a copilot-setup-steps.yml file specifying one with the runs-on attribute. See the docs for more details.

This PR fixes a sensitive-data handling bug in wolfCLU_ecparam by zeroizing a DER-encoded EC private-key buffer prior to freeing it, preventing private-key material from remaining in heap memory after XFREE.

Changes:

  • Add a defensive derSz > 0 check before zeroizing.
  • Call wolfCLU_ForceZero(der, derSz) before freeing the DER buffer in the ecparam -genkey ... -outform der path.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/ecparam/clu_ecparam.c
@MarkAtwood
MarkAtwood force-pushed the fix/ecparam-forcezero-der-privkey branch from a80d7c7 to 2fc8bed Compare September 24, 2026 22:47
@MarkAtwood
MarkAtwood marked this pull request as ready for review September 24, 2026 23:52
@aidankeefe2022
aidankeefe2022 merged commit 16c4a9f into wolfSSL:main Oct 1, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants