Chrome · SSL
CVE-2026-14103
UAF in SSL
Overview
Low
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Changed Functions
| Function | Change | Notes |
|---|---|---|
fornet/ssl/client_cert_matcher.cc |
modified | |
ifnet/ssl/client_cert_matcher.cc |
modified |
Files Changed
net/ssl/client_cert_matcher.cc
Patch
From 619f5c794620b6541a41cedd6d22e469a2b3df54 Mon Sep 17 00:00:00 2001 From: Matt Mueller <[email protected]> Date: Thu, 21 May 2026 19:52:09 -0700 Subject: [PATCH] client_cert_matcher: fix break from nested loop Bug: 513465245 Change-Id: I9eab79863695c44b46515574080b4f543b057165 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7862009 Reviewed-by: Nick Harper <[email protected]> Commit-Queue: Matt Mueller <[email protected]> Cr-Commit-Position: refs/heads/main@{#1634691} --- diff --git a/net/ssl/client_cert_matcher.cc b/net/ssl/client_cert_matcher.cc index 6aa0cc3d..cdfd5e39 100644 --- a/net/ssl/client_cert_matcher.cc +++ b/net/ssl/client_cert_matcher.cc @@ -17,6 +17,31 @@ namespace { +// Searches in `sources` for a certificate with subject matching +// `current_issuer`. If found, the certificate is added to `intermediates`, +// `current_issuer` and `current_subject` are updated to the values from the +// certificate, and true is returned. +bool FindIssuerCert(const ClientCertIssuerSourceCollection& sources, + std::vector<bssl::UniquePtr<CRYPTO_BUFFER>>* intermediates, + base::span<const uint8_t>* current_issuer, + base::span<const uint8_t>* current_subject) { + for (const auto& source : sources) { + std::vector<bssl::UniquePtr<CRYPTO_BUFFER>> issuers = + source->GetCertsByName(*current_issuer); + for (auto& issuer : issuers) { + if (asn1::ExtractIssuerAndSubjectFromDERCert( + x509_util::CryptoBufferAsSpan(issuer.get()), current_issuer, + current_subject)) { + // The first matching issuer found at each step is used. This algorithm + // doesn't do a full graph exploration. + intermediates->push_back(std::move(issuer)); + return true; + } + } + } + return false; +} + bool MatchClientCertificateIssuers( X509Certificate* cert, const std::vector<std::string>& cert_authorities, @@ -54,24 +79,8 @@ } // Look for an issuer of the current cert. - bool found_issuer = false; - for (const auto& source : sources) { - std::vector<bssl::UniquePtr<CRYPTO_BUFFER>> issuers = - source->GetCertsByName(current_issuer); - for (auto& issuer : issuers) { - if (asn1::ExtractIssuerAndSubjectFromDERCert( - x509_util::CryptoBufferAsSpan(issuer.get()), ¤t_issuer, - ¤t_subject)) { - // The first issuer found at each step is used. This algorithm doesn't - // do a full graph exploration. - found_issuer = true; - intermediates->push_back(std::move(issuer)); - break; - } - } - } - - if (!found_issuer) { + if (!FindIssuerCert(sources, intermediates, ¤t_issuer, + ¤t_subject)) { // No issuers were found, give up. return false; }
Loading diff…
Original Bug Report
The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.
References
On This Page