<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/CryptoPkg/Library/BaseCryptLib/Pk/CryptAuthenticode.c, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2025-04-21T02:14:50+00:00</updated>
<entry>
<title>CryptoPkg: Resolve CodeQL Errors</title>
<updated>2025-04-21T02:14:50+00:00</updated>
<author>
<name>Oliver Smith-Denny</name>
<email>osde@microsoft.com</email>
</author>
<published>2025-04-18T20:51:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2e85d12685b950dc8ff54130f9d623a120f852d6'/>
<id>urn:sha1:2e85d12685b950dc8ff54130f9d623a120f852d6</id>
<content type='text'>
This patch updates several CodeQL errors for potential null pointer
access and unguarded header conclusion across production and test
code that have been flagged in the build/security tab in GitHub.

Signed-off-by: Oliver Smith-Denny &lt;osde@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/Library/BaseCryptLib: Update internal functions/variables</title>
<updated>2022-10-24T07:49:43+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2022-10-04T03:45:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=8f8372439d8ec5f565dbda1548c18deb068e0080'/>
<id>urn:sha1:8f8372439d8ec5f565dbda1548c18deb068e0080</id>
<content type='text'>
* Update BaseCryptLib internal worker functions to be 'STATIC'
* Update BaseCryptLib internal working functions to not use EFIAPI
* Add GLOBAL_REMOVE_IF_UNREFERENCED to BaseCryptLib global variables

Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Cc: Xiaoyu Lu &lt;xiaoyu1.lu@intel.com&gt;
Cc: Guomin Jiang &lt;guomin.jiang@intel.com&gt;
Cc: Christopher Zurcher &lt;christopher.zurcher@microsoft.com&gt;
Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Reviewed-by: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Apply uncrustify changes</title>
<updated>2021-12-07T17:24:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2021-12-05T22:53:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=7c342378317039e632d9a1a5d4cf7c21aec8cb7a'/>
<id>urn:sha1:7c342378317039e632d9a1a5d4cf7c21aec8cb7a</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3737

Apply uncrustify changes to .c/.h files in the CryptoPkg package

Cc: Andrew Fish &lt;afish@apple.com&gt;
Cc: Leif Lindholm &lt;leif@nuviainc.com&gt;
Cc: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
Reviewed-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/BaseCryptLib: fix NULL dereference (CVE-2019-14584)</title>
<updated>2020-10-21T06:32:46+00:00</updated>
<author>
<name>Jian J Wang</name>
<email>jian.j.wang@intel.com</email>
</author>
<published>2019-04-25T15:42:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=26442d11e620a9e81c019a24a4ff38441c64ba10'/>
<id>urn:sha1:26442d11e620a9e81c019a24a4ff38441c64ba10</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1914

AuthenticodeVerify() calls OpenSSLs d2i_PKCS7() API to parse asn encoded
signed authenticode pkcs#7 data. when this successfully returns, a type
check is done by calling PKCS7_type_is_signed() and then
Pkcs7-&gt;d.sign-&gt;contents-&gt;type is used. It is possible to construct an asn1
blob that successfully decodes and have d2i_PKCS7() return a valid pointer
and have PKCS7_type_is_signed() also return success  but have Pkcs7-&gt;d.sign
be a NULL pointer.

Looking at how PKCS7_verify() [inside of OpenSSL] implements checking for
pkcs7 structs it does the following:
- call PKCS7_type_is_signed()
- call PKCS7_get_detached()
Looking into how PKCS7_get_detatched() is implemented, it checks to see if
p7-&gt;d.sign is NULL or if p7-&gt;d.sign-&gt;contents-&gt;d.ptr is NULL.

As such, the fix is to do the same as OpenSSL after calling d2i_PKCS7().
- Add call to PKS7_get_detached() to existing error handling

Cc: Xiaoyu Lu &lt;xiaoyux.lu@intel.com&gt;
Cc: Guomin Jiang &lt;guomin.jiang@intel.com&gt;
Cc: Jiewen Yao &lt;jiewen.yao@intel.com&gt;
Cc: Laszlo Ersek &lt;lersek@redhat.com&gt;
Signed-off-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Reviewed-by: Laszlo Ersek &lt;lersek@redhat.com&gt;
Reviewed-by: Jiewen Yao &lt;Jiewen.yao@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Replace BSD License with BSD+Patent License</title>
<updated>2019-04-09T16:10:22+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2019-04-03T23:03:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2009f6b4c5cbd7dda95a2594288405224173d239'/>
<id>urn:sha1:2009f6b4c5cbd7dda95a2594288405224173d239</id>
<content type='text'>
https://bugzilla.tianocore.org/show_bug.cgi?id=1373

Replace BSD 2-Clause License with BSD+Patent License.  This change is
based on the following emails:

  https://lists.01.org/pipermail/edk2-devel/2019-February/036260.html
  https://lists.01.org/pipermail/edk2-devel/2018-October/030385.html

RFCs with detailed process for the license change:

  V3: https://lists.01.org/pipermail/edk2-devel/2019-March/038116.html
  V2: https://lists.01.org/pipermail/edk2-devel/2019-March/037669.html
  V1: https://lists.01.org/pipermail/edk2-devel/2019-March/037500.html

Contributed-under: TianoCore Contribution Agreement 1.1
Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Reviewed-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix typos in comments</title>
<updated>2016-11-07T15:21:22+00:00</updated>
<author>
<name>Gary Lin</name>
<email>glin@suse.com</email>
</author>
<published>2016-10-19T07:01:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2998af862469c6a05657e169d7def6f55420caad'/>
<id>urn:sha1:2998af862469c6a05657e169d7def6f55420caad</id>
<content type='text'>
- intialized -&gt; initialized
- componenet -&gt; component
- compoents -&gt; components
- FAlSE -&gt; FALSE
- responsiblity -&gt; responsibility
- validility -&gt; validity
- procudure -&gt; procedure
- pamameter -&gt; parameter
- randome -&gt; random
- buiild -&gt; build

Cc: Ting Ye &lt;ting.ye@intel.com&gt;
Cc: Qin Long &lt;qin.long@intel.com&gt;
Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: Gary Lin &lt;glin@suse.com&gt;
Reviewed-by: Qin Long &lt;qin.long@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/BaseCryptLib: Clean up checking of PKCS#7 contents type</title>
<updated>2015-10-29T14:16:37+00:00</updated>
<author>
<name>David Woodhouse</name>
<email>David.Woodhouse@intel.com</email>
</author>
<published>2015-10-29T14:16:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=e6eaada46861a2a7c5a5370d74dafc731a587786'/>
<id>urn:sha1:e6eaada46861a2a7c5a5370d74dafc731a587786</id>
<content type='text'>
Use the new OBJ_get0_data() accessor to compare the data, and actually
check the length of the object too.

Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: David Woodhouse &lt;David.Woodhouse@intel.com&gt;
Tested-by: Laszlo Ersek &lt;lersek@redhat.com&gt;
Reviewed-by: Qin Long &lt;qin.long@intel.com&gt;

git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@18702 6f19259b-4bc3-4df7-8a09-765794883524
</content>
</entry>
<entry>
<title>CryptoPkg: Wrapper files updates to support openssl-1.0.2c</title>
<updated>2015-06-16T00:54:16+00:00</updated>
<author>
<name>Qin Long</name>
<email>qin.long@intel.com</email>
</author>
<published>2015-06-16T00:54:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=1463ce18ca7c4f971c08cc6341dbb0adb25c831a'/>
<id>urn:sha1:1463ce18ca7c4f971c08cc6341dbb0adb25c831a</id>
<content type='text'>
This patch updates some support header and wrapper files to support
openssl-1.0.2c build, and correct some openssl API usages and
boundary check.

Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: Qin Long &lt;qin.long@intel.com&gt;
Reviewed-by: Ard Biesheuvel &lt;ard.biesheuvel@linaro.org&gt;

git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@17635 6f19259b-4bc3-4df7-8a09-765794883524
</content>
</entry>
<entry>
<title>CryptoPkg Updates to support RFC3161 timestamp signature verification. </title>
<updated>2014-11-12T08:51:45+00:00</updated>
<author>
<name>Qin Long</name>
<email>qin.long@intel.com</email>
</author>
<published>2014-11-12T08:51:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2ac68e8b549b646607149919a2780bcd7234d92d'/>
<id>urn:sha1:2ac68e8b549b646607149919a2780bcd7234d92d</id>
<content type='text'>
The main changes includes:
1. Enabling SHA384 and SHA512 digest algorithm; (Sha512.c)
2. RFC 3161 timestamp signature verification support; (CryptTs.c)
3. Fixed one ASN.1 length encoding issue in Authenticode verification routine. (CryptAuthenticode.c)
4. Add the corresponding test cases in Cryptest utility (SHA384 &amp; SHA512 &amp; Timestamp verification)

Contributed-under: TianoCore Contribution Agreement 1.0

Signed-off-by: Qin Long &lt;qin.long@intel.com&gt; 
Reviewed-by: Guo Dong &lt;guo.dong@intel.com&gt;
Reviewed-by: Ting Ye &lt;ting.ye@intel.com&gt;

git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@16339 6f19259b-4bc3-4df7-8a09-765794883524
</content>
</entry>
<entry>
<title>Clean up code.</title>
<updated>2014-08-07T07:56:31+00:00</updated>
<author>
<name>qlong</name>
<email>qlong</email>
</author>
<published>2014-08-07T07:56:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=0e24145420fc1c4d38ca22437bec44ee32d1465b'/>
<id>urn:sha1:0e24145420fc1c4d38ca22437bec44ee32d1465b</id>
<content type='text'>
Contributed-under: TianoCore Contribution Agreement 1.0
Signed off by: Long Qin &lt;qin.long@intel.com&gt;
Reviewed by: Eric Dong &lt;eric.dong@intel.com&gt;

git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@15768 6f19259b-4bc3-4df7-8a09-765794883524
</content>
</entry>
</feed>
