Skip to content

fix(pdf): validate the complete AES padding trailer - #1145

Merged
andiwand merged 2 commits into
mainfrom
review/127-pdf-aes-padding
Oct 6, 2026
Merged

andiwand merged 2 commits into
mainfrom
review/127-pdf-aes-padding

Conversation

@andiwand

@andiwand andiwand commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

🤖 Generated with Claude Code

PDF AES decryption removed a trailer based only on its final byte, truncating plaintext when preceding padding bytes disagreed. Check the complete padding before stripping it and retain the existing lenient behavior for malformed trailers. Use fixed-width counters throughout the password algorithms.

Validation: the new regression fails on the parent for malformed padding lengths 2–16 and passes after the fix; all 79 encryption, parser and PDF-file tests pass. LLVM 22 clang-tidy passes.

@andiwand
andiwand force-pushed the review/126-analysis-policy branch from 9ff0b9f to 22862fd Compare October 6, 2026 14:04
Base automatically changed from review/126-analysis-policy to main October 6, 2026 14:07
@andiwand
andiwand force-pushed the review/127-pdf-aes-padding branch from 1a2b4f4 to ab3e889 Compare October 6, 2026 14:31
@andiwand
andiwand merged commit 7ea2e37 into main Oct 6, 2026
29 checks passed
@andiwand
andiwand deleted the review/127-pdf-aes-padding branch October 6, 2026 14:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant