From 57f09bb4bb051d3bc2a1abd36e9525313d5cd408 Mon Sep 17 00:00:00 2001 From: Alex Gaynor Date: Wed, 18 Feb 2026 07:46:15 -0500 Subject: [PATCH] Fix buffer overflow in DTLS cookie generation callback (#1479) The cookie generate callback copied user-returned bytes into a fixed-size native buffer without enforcing a maximum length. A callback returning more than DTLS1_COOKIE_LENGTH bytes would overflow the OpenSSL-provided buffer, corrupting adjacent memory. Co-authored-by: Claude Opus 4.6 Upstream: https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408 CVE: CVE-2026-27459 [thomas: backported, stripped tests and changelog] Signed-off-by: Thomas Perale --- src/OpenSSL/SSL.py | 7 +++++++ 1 files changed, 7 insertions(+) diff --git a/src/OpenSSL/SSL.py b/src/OpenSSL/SSL.py index a6263c4..2e4da78 100644 --- a/src/OpenSSL/SSL.py +++ b/src/OpenSSL/SSL.py @@ -716,11 +716,18 @@ class _CookieGenerateCallbackHelper(_CallbackExceptionHelper): def __init__(self, callback: _CookieGenerateCallback) -> None: _CallbackExceptionHelper.__init__(self) + max_cookie_len = getattr(_lib, "DTLS1_COOKIE_LENGTH", 255) + @wraps(callback) def wrapper(ssl, out, outlen): # type: ignore[no-untyped-def] try: conn = Connection._reverse_mapping[ssl] cookie = callback(conn) + if len(cookie) > max_cookie_len: + raise ValueError( + f"Cookie too long (got {len(cookie)} bytes, " + f"max {max_cookie_len})" + ) out[0 : len(cookie)] = cookie outlen[0] = len(cookie) return 1 -- 2.43.0