Sitelet https://github.com/libssh2/libssh2/pull/2230
Skip to content

kex: harden remote public key length check in kex_mlkem_nistp() - #2230

Draft
vszakats wants to merge 3 commits into
libssh2:masterfrom
vszakats:kex-remote-pubkey-len
Draft

vszakats wants to merge 3 commits into
libssh2:masterfrom
vszakats:kex-remote-pubkey-len

Conversation

@vszakats

@vszakats vszakats commented Jul 6, 2026

Copy link
Copy Markdown
Member

Cap to 256 KiB.

Follow-up to 3ba252e #1644

@vszakats
vszakats marked this pull request as draft July 6, 2026 13:11
This reverts commit 15d4c9d.

No CI jobs seem to run this code.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the ML-KEM + NIST-P hybrid key exchange path by adding an explicit upper bound check for the remote server’s concatenated public key blob in kex_mlkem_nistp(), aiming to reduce DoS risk from overly large inputs.

Changes:

  • Add a maximum-length guard (256 KiB) for server_public_key_len in kex_mlkem_nistp().

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/kex.c
Comment on lines +2019 to 2023
if(server_public_key_len <= mlkem_cipher_len ||
server_public_key_len > (256 * 1024)) {
ret = ssh2_err(session, LIBSSH2_ERROR_HOSTKEY_INIT,
"Unexpected mlkemnistp server public key length");
goto clean_exit;

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't get this. (except the errmsg, which is wrong, I put in the queue)

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

errmsg fixed via #2234

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants