From: Daiki Ueno Date: Wed, 22 Dec 2021 08:12:25 +0000 (+0100) Subject: wrap_nettle_hash_fast: avoid calling _update with zero-length input X-Git-Tag: 3.7.3~13^2 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=3db352734472d851318944db13be73da61300568;p=thirdparty%2Fgnutls.git wrap_nettle_hash_fast: avoid calling _update with zero-length input As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. Signed-off-by: Daiki Ueno --- diff --git a/lib/nettle/mac.c b/lib/nettle/mac.c index f9d4d7a8df..35e070fab0 100644 --- a/lib/nettle/mac.c +++ b/lib/nettle/mac.c @@ -788,7 +788,9 @@ static int wrap_nettle_hash_fast(gnutls_digest_algorithm_t algo, if (ret < 0) return gnutls_assert_val(ret); - ctx.update(&ctx, text_size, text); + if (text_size > 0) { + ctx.update(&ctx, text_size, text); + } ctx.digest(&ctx, ctx.length, digest); return 0;