Update hkdf.c to avoid potentially vulnerable code pattern.

Change-Id: I190fcdb0b9667b0ac6f490b36edc63237af7fffb
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/59905
Reviewed-by: David Benjamin <davidben@google.com>
This commit is contained in:
Nicky Mouha
2023-05-18 23:05:56 +00:00
committed by David Benjamin
parent dd5219451c
commit 47b2fefb03
+1 -1
View File
@@ -94,7 +94,7 @@ int HKDF_expand(uint8_t *out_key, size_t out_len, const EVP_MD *digest,
}
todo = digest_len;
if (done + todo > out_len) {
if (todo > out_len - done) {
todo = out_len - done;
}
OPENSSL_memcpy(out_key + done, previous, todo);