Skip to content

mbedtls: release the previous PSA key on re-init, map HMAC init errors - #825

Merged
pabuhler merged 1 commit into
cisco:mainfrom
vikramdattu:fix/hmac-mbedtls-init
Oct 9, 2026
Merged

pabuhler merged 1 commit into
cisco:mainfrom
vikramdattu:fix/hmac-mbedtls-init

Conversation

@vikramdattu

@vikramdattu vikramdattu commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Two problems in the mbedTLS (PSA) backend:

  1. srtp_hmac_mbedtls_init() and srtp_aes_gcm_mbedtls_context_init() import a new PSA key without destroying the key from an earlier init. Re-keying an auth or GCM cipher therefore leaks one PSA key slot per init. The AES-ICM backend already destroys the old key first; this applies the same pattern to both.
  2. srtp_hmac_mbedtls_init() returns the raw psa_status_t (a negative PSA error) as an srtp_err_status_t. It now returns srtp_err_status_auth_fail, as the OpenSSL and wolfSSL backends do.

This brings main in line with 2_x_dev, whose mbedTLS 4 / PSA path (#813) already destroys the previous key before importing and returns srtp_err_status_auth_fail.

Tests (test_srtp, mbedTLS builds only):

  • srtp_hmac_mbedtls_reinit_does_not_leak_key, srtp_aes_gcm_mbedtls_reinit_does_not_leak_key: count volatile PSA keys with mbedtls_psa_get_stats() around two inits and the dealloc.
  • srtp_hmac_mbedtls_init_failure_returns_srtp_status: a zero-length HMAC key, which PSA rejects, must return srtp_err_status_auth_fail.

All three fail without the fix and pass with it. Tested on mbedTLS 4.0.0 (as in the CI workflow): all 13 ctest suites pass, and ./format.sh -d with clang-format 14 is clean. A non-mbedTLS build compiles with the tests guarded out.

mbedtls_psa_get_stats() is an mbedTLS extension, and its fields are MBEDTLS_PRIVATE. The tests depend on it only under #ifdef MBEDTLS.

@vikramdattu

Copy link
Copy Markdown
Contributor Author

@pabuhler PTAL

Comment thread crypto/cipher/aes_gcm_mbedtls.c
Comment thread crypto/hash/hmac_mbedtls.c
srtp_hmac_mbedtls_init() and srtp_aes_gcm_mbedtls_context_init()
imported a new PSA key without destroying the one from a previous init,
so re-keying an auth or a GCM cipher leaked a key slot each time.
Destroy the old key first, as the AES-ICM backend already does.

srtp_hmac_mbedtls_init() also returned the raw psa_status_t, a negative
PSA error, as an srtp_err_status_t. Return srtp_err_status_auth_fail,
matching the OpenSSL and wolfSSL backends.

test_srtp gains mbedTLS-only tests that count volatile PSA keys around a
double init, and check the status of a rejected (zero-length) HMAC key.
@vikramdattu
vikramdattu force-pushed the fix/hmac-mbedtls-init branch from d8a3a61 to 80c827b Compare October 9, 2026 07:21
@pabuhler
pabuhler merged commit 7071fba into cisco:main Oct 9, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants