Skip to content

Low-severity security hardening across TLS, X.509, PKCS#7/12, DTLS 1.3, QUIC, and the sniffer#10878

Open
aidangarske wants to merge 38 commits into
wolfSSL:masterfrom
aidangarske:fenrir-tls-triage
Open

Low-severity security hardening across TLS, X.509, PKCS#7/12, DTLS 1.3, QUIC, and the sniffer#10878
aidangarske wants to merge 38 commits into
wolfSSL:masterfrom
aidangarske:fenrir-tls-triage

Conversation

@aidangarske

Copy link
Copy Markdown
Member
F-6559, F-6731, F-6730, F-6723, F-6711, F-4112, F-4111, F-6328, F-6704, F-6705, F-5585, F-6712, F-5625, F-6557,
F-5729, F-6708, F-4154, F-4155, F-5755, F-5859, F-5860, F-6523, F-5626, F-3886, F-4149, F-4150, F-4616, F-4617,
F-1839, F-1842, F-6729, F-6303

This comment was marked as resolved.

@aidangarske
aidangarske marked this pull request as ready for review July 10, 2026 22:44
@aidangarske
aidangarske requested a review from dgarske July 10, 2026 22:55
@github-actions

Copy link
Copy Markdown

retest this please

@github-actions

github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m0plus

  • FLASH: .text +64 B (+0.1%, 64,219 B / 262,144 B, total: 24% used)

gcc-arm-cortex-m3

  • FLASH: .text +36 B (+0.0%, 122,531 B / 262,144 B, total: 47% used)

gcc-arm-cortex-m4

  • FLASH: .rodata.CSWTCH.1 +28 B, .rodata.str1.1 +332 B, .rodata.wolfSSL_ERR_reason_error_string.str1.1 +31 B, .text +64 B (+0.2%, 200,789 B / 262,144 B, total: 77% used)

gcc-arm-cortex-m4-crypto-only

  • FLASH: .rodata.CSWTCH.1 +28 B, .rodata.str1.1 +332 B (+0.2%, 174,928 B / 262,144 B, total: 67% used)

gcc-arm-cortex-m4-dtls13

  • FLASH: .rodata +12 B, .text +128 B (+0.1%, 181,028 B / 1,048,576 B, total: 17% used)

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .rodata +416 B, .text +512 B (+0.1%, 772,076 B / 1,048,576 B, total: 74% used)

gcc-arm-cortex-m4-pkcs7

  • FLASH: .rodata.CSWTCH.1 +28 B, .rodata.str1.1 +332 B, .text +448 B (+0.4%, 213,396 B / 262,144 B, total: 81% used)

gcc-arm-cortex-m4-pq

  • FLASH: .rodata +412 B, .text +256 B (+0.2%, 280,064 B / 1,048,576 B, total: 27% used)

gcc-arm-cortex-m4-rsa-only

  • FLASH: .rodata +408 B, .text +512 B (+0.3%, 325,912 B / 1,048,576 B, total: 31% used)

gcc-arm-cortex-m4-tls12

  • FLASH: .text +64 B (+0.1%, 123,291 B / 262,144 B, total: 47% used)

gcc-arm-cortex-m4-tls13

  • FLASH: .rodata.CSWTCH.1 +28 B, .rodata.str1.1 +332 B, .rodata.wolfSSL_ERR_reason_error_string.str1.1 +31 B, .text +256 B (+0.3%, 236,743 B / 262,144 B, total: 90% used)

gcc-arm-cortex-m7

  • FLASH: .rodata.CSWTCH.1 +28 B, .rodata.str1.1 +332 B, .rodata.wolfSSL_ERR_reason_error_string.str1.1 +31 B, .text +64 B (+0.2%, 200,789 B / 262,144 B, total: 77% used)

gcc-arm-cortex-m7-pq

  • FLASH: .rodata +412 B, .text +256 B (+0.2%, 280,640 B / 1,048,576 B, total: 27% used)

gcc-arm-cortex-m7-tls13

  • FLASH: .rodata.CSWTCH.1 +28 B, .rodata.str1.1 +332 B, .rodata.wolfSSL_ERR_reason_error_string.str1.1 +31 B, .text +256 B (+0.3%, 236,807 B / 262,144 B, total: 90% used)

linuxkm-pie

  • Data: __patchable_function_entries +408 B (+1.6%, 25,960 B)

linuxkm-standard

  • Data: __patchable_function_entries +392 B (+0.8%, 48,616 B)

stm32-sim-stm32h753

@aidangarske
aidangarske removed the request for review from dgarske July 15, 2026 22:47
@JacobBarthelmeh

Copy link
Copy Markdown
Contributor

Retest this please Jenkins

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #10878

Scan targets checked: wolfcrypt-bugs, wolfcrypt-port-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src

Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Findings are non-blocking.

Comment thread src/ssl.c Outdated
@aidangarske aidangarske assigned SparkiDev and unassigned aidangarske Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants