Files
openwrt_yocto/meta-openembedded/meta-networking/recipes-connectivity/wolfssl/files/CVE-2025-7395-2.patch
T
francis.wang 4c86c082a2 Initial commit: OpenWrt-Yocto monorepo
Combine poky (Yocto scarthgap), meta-openembedded (scarthgap), and
meta-openwrt into a single repository.

Components:
- poky/             Yocto core framework (BitBake + OE-Core)
- meta-openembedded/ Community layers (meta-oe, meta-python, meta-networking)
- meta-openwrt/     OpenWrt customization layer
- setup-env.sh      One-click build environment setup
- README.md         Project documentation
2026-07-11 13:28:01 +08:00

28 lines
1.3 KiB
Diff

From aad4e7c38f3784942923f4871d61a7e41d3de842 Mon Sep 17 00:00:00 2001
From: Brett <bigbrett@users.noreply.github.com>
Date: Wed, 4 Jun 2025 15:48:15 -0600
Subject: [PATCH] prevent apple native cert validation from overriding error
codes other than ASN_NO_SIGNER_E
CVE: CVE-2025-7395
Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/bc8eeea703253bd65d472a9541b54fef326e8050]
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
---
src/internal.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/src/internal.c b/src/internal.c
index 2b090382f..79f584a0a 100644
--- a/src/internal.c
+++ b/src/internal.c
@@ -15991,7 +15991,8 @@ int ProcessPeerCerts(WOLFSSL* ssl, byte* input, word32* inOutIdx,
/* If we can't validate the peer cert chain against the CAs loaded
* into wolfSSL, try to validate against the system certificates
* using Apple's native trust APIs */
- if ((ret != 0) && (ssl->ctx->doAppleNativeCertValidationFlag)) {
+ if ((ret == ASN_NO_SIGNER_E) &&
+ (ssl->ctx->doAppleNativeCertValidationFlag)) {
if (DoAppleNativeCertValidation(ssl, args->certs,
args->totalCerts)) {
WOLFSSL_MSG("Apple native cert chain validation SUCCESS");