[tls] Reject a duplicate ServerHelloDone

A duplicate ServerHelloDone could cause the server validation pending
operation to be incremented twice but only decremented once, leaving
the total pending operation count above zero and thereby causing any
future "sync" command with no timeout to wait indefinitely.

Fix by rejecting ServerHelloDone if validation is already pending.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-08-27 13:08:39 +01:00
parent 61a75eca5f
commit 26f46a2b4f
+6 -1
View File
@@ -2825,13 +2825,18 @@ static int tls_new_server_hello_done ( struct tls_connection *tls,
} __attribute__ (( packed )) *hello_done = data;
int rc;
/* Sanity check */
/* Sanity checks */
if ( sizeof ( *hello_done ) != len ) {
DBGC ( tls, "TLS %p received overlength Server Hello Done\n",
tls );
DBGC_HD ( tls, data, len );
return -EINVAL_HELLO_DONE;
}
if ( is_pending ( &tls->server.validation ) ) {
DBGC ( tls, "TLS %p received duplicate Server Hello Done\n",
tls );
return -EINVAL_HELLO_DONE;
}
/* Begin certificate validation */
if ( ( rc = create_validator ( &tls->server.validator,