]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
ktls: Reject attempts to enable AES-CBC with TLS 1.3.
authorJohn Baldwin <jhb@FreeBSD.org>
Wed, 13 Oct 2021 19:12:58 +0000 (12:12 -0700)
committerJohn Baldwin <jhb@FreeBSD.org>
Tue, 23 Nov 2021 23:11:44 +0000 (15:11 -0800)
commit0053fedc1b4790f2e094c326adef95302c105f8b
tree106618f25324e68a0b3eb2e6655993011a03dd4b
parent412a8b92d9c0490ba700f5ea4f676a16778643bd
ktls: Reject attempts to enable AES-CBC with TLS 1.3.

AES-CBC cipher suites are not supported in TLS 1.3.

Reported by: syzbot+ab501c50033ec01d53c6@syzkaller.appspotmail.com
Reviewed by: tuexen, markj
Differential Revision: https://reviews.freebsd.org/D32404

(cherry picked from commit a63752cce6462d08bbec08cad931d70dec2f5b4c)
sys/kern/uipc_ktls.c