Skip to content

Fix/ai http ca use after free - #719

Merged
shiliu-yang merged 2 commits into
masterfrom
fix/ai-http-ca-use-after-free
Sep 28, 2026
Merged

shiliu-yang merged 2 commits into
masterfrom
fix/ai-http-ca-use-after-free

Conversation

@shiliu-yang

Copy link
Copy Markdown
Contributor

PR 描述/PR description

[在此详细描述 PR 的内容]/[Describe the PR content in detail here]

代码质量/Code Quality:

在本次拉取请求中,我已考虑以下事项 As part of this pull request, I've considered the following:

  • 确保代码注释和文档清晰,并使用英文注释以保证代码可读性。Ensure that the code comments and documentation are clear, and use English for comments to ensure code readability.
  • 确保文件头遵循文件头格式。Ensure that the file header follows the File Header Format.
  • 确保函数头遵循 Doxygen 格式。Ensure that function headers follow the Doxygen format as specified in Comments.
  • 已查阅 编码风格指南,并核查代码风格合规性,包括缩进、空格、命名规范及其他风格要求。 Reviewed the Coding Style Guide and verified code style compliance, including indentation, spacing, naming conventions, and other style guidelines.
  • 已使用代码格式化工具确保符合 TuyaOpen 编码规范。Have used the code-formatting source code formatting tool to ensure compliance with TuyaOpen coding standards.

http_session_send() freed the CA buffer returned by
tuya_iotdns_query_domain_certs() right after TUYA_TRANSPORTER_SET_TLS_CONFIG,
but the TLS layer only keeps the pointer: tuya_tls_config_set() memcpy-s the
config struct, not the certificate data, and mbedtls_x509_crt_parse() does not
run until tuya_transporter_connect().

The freed DER block is typically reused by the allocations inside connect
(socket, mbedtls contexts), so mbedtls reads garbage and fails with
MBEDTLS_ERR_X509_INVALID_FORMAT (-0x2180) -- the outer SEQUENCE tag is no
longer 0x30. TLS connections to CDN hosts then fail, e.g. the US-region
*.cdn5th.com TTS download, while CN region often survives because the block
happens to stay intact.

Free cacert after connect returns instead, and reject an empty CA up front the
way http_session.c already does.
@shiliu-yang
shiliu-yang merged commit b021da6 into master Sep 28, 2026
2 checks passed
@shiliu-yang
shiliu-yang deleted the fix/ai-http-ca-use-after-free branch September 28, 2026 08:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants