cms: Reject AES-256-CBC IV with invalid length
details
- Finding IDs
- F-NITRO-IVLEN-001
- Status
- merged
- Reported date
- Rationale
- rejects malformed CMS AES-256-CBC IV lengths before decryption so short IV buffers cannot reach EVP_DecryptInit_ex unchecked.
- PR opened by
- @mariusknaust
- PR state observed
- closed; GitHub merged: true; 2026-09-24
- PR observation basis
- Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
- Contribution boundary
- Report-associated upstream work; @1seal code authorship is not claimed. Credit, where recorded, is a separate fact.
F-NITRO-IVLEN-001: Memory safety. A short IV buffer reaches a cryptographic out-of-bounds read. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-NITRO-IVLEN-001
Security area (1seal assessment): Memory safety. Rejecting a short AES IV prevents the decrypt initializer from reading beyond the supplied buffer. Reviewed 21 Sep 2026.