Skip to content

Replace XMEMCMP with ConstantCompare for ticket MAC verification#9898

Merged
douzzer merged 1 commit intowolfSSL:masterfrom
julek-wolfssl:fenrir/15
Mar 7, 2026
Merged

Replace XMEMCMP with ConstantCompare for ticket MAC verification#9898
douzzer merged 1 commit intowolfSSL:masterfrom
julek-wolfssl:fenrir/15

Conversation

@julek-wolfssl
Copy link
Member

F-15

Copilot AI review requested due to automatic review settings March 6, 2026 07:48
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Replaces a non-constant-time MAC comparison with a constant-time comparison during TLS ticket MAC verification.

Changes:

  • Swap XMEMCMP for ConstantCompare when verifying the computed ticket MAC.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@philljj philljj added the For This Release Release version 5.9.0 label Mar 6, 2026
@douzzer douzzer added the Staged Staged for merge pending final test results and review label Mar 6, 2026
@douzzer douzzer merged commit 6c37629 into wolfSSL:master Mar 7, 2026
441 of 443 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

For This Release Release version 5.9.0 Staged Staged for merge pending final test results and review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants