From 825d508a4b688821e99561b72a842c81c93b84a5 Mon Sep 17 00:00:00 2001 From: jsing <> Date: Mon, 11 May 2020 18:03:51 +0000 Subject: Add record version checks. When legacy version is below TLSv1.2 ensure that the record version is SSL3/TLS, however when the legacy version is set to TLSv1.2 require this specifically. ok beck@ tb@ --- src/lib/libssl/tls13_record_layer.c | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) (limited to 'src/lib/libssl/tls13_record_layer.c') diff --git a/src/lib/libssl/tls13_record_layer.c b/src/lib/libssl/tls13_record_layer.c index e7650b1ecc..8ca52d0b7f 100644 --- a/src/lib/libssl/tls13_record_layer.c +++ b/src/lib/libssl/tls13_record_layer.c @@ -1,4 +1,4 @@ -/* $OpenBSD: tls13_record_layer.c,v 1.39 2020/05/11 17:46:46 jsing Exp $ */ +/* $OpenBSD: tls13_record_layer.c,v 1.40 2020/05/11 18:03:51 jsing Exp $ */ /* * Copyright (c) 2018, 2019 Joel Sing * @@ -769,11 +769,18 @@ tls13_record_layer_read_record(struct tls13_record_layer *rl) goto err; } - if ((ret = tls13_record_recv(rl->rrec, rl->cb.wire_read, rl->cb_arg)) <= 0) + if ((ret = tls13_record_recv(rl->rrec, rl->cb.wire_read, rl->cb_arg)) <= 0) { + switch (ret) { + case TLS13_IO_RECORD_VERSION: + return tls13_send_alert(rl, SSL_AD_PROTOCOL_VERSION); + } return ret; - - /* XXX - record version checks. */ - + } + + if (rl->legacy_version == TLS1_2_VERSION && + tls13_record_version(rl->rrec) != TLS1_2_VERSION) + return tls13_send_alert(rl, SSL_AD_PROTOCOL_VERSION); + content_type = tls13_record_content_type(rl->rrec); /* -- cgit v1.2.3-55-g6feb