Skip to content

report malformed OCSPResp and OCSPReq input as IOException - #2468

Open
rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:ocsp-malformed-input-ioexception
Open

rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:ocsp-malformed-input-ioexception

Conversation

@rootvector2

Copy link
Copy Markdown
Contributor

OCSPResp(byte[]) and OCSPReq(byte[]) only catch IllegalArgumentException, ClassCastException and ASN1Exception around the decode, so a top-level SEQUENCE that is empty or truncated makes OCSPResponse/OCSPRequest read seq.getObjectAt(0) out of bounds and the ArrayIndexOutOfBoundsException escapes the declared throws IOException (an OCSP client parsing a response, or a responder parsing a request, crashes instead of rejecting the input). Both now surface any RuntimeException from the decode as CertIOException, matching what X509CertificateHolder.parseBytes and X509CRLHolder.parseStream already do. Found while checking the cert byte[] parse entry points for the RuntimeException guard those two classes carry; new OCSPResp(new byte[]{0x30, 0x00}) reproduces it, and the added OCSPMalformedInputTest covers empty/truncated/non-SEQUENCE encodings for both parsers plus a valid request/response round trip.

AI tooling was used to help prepare this change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant