Skip to content

bug: decoding fixed bytes into fixed array #735

Description

@karalabe

TL;DR: https://go.dev/play/p/pllZCYDLQ1G

When decoding a 31 byte array from CBOR into a [32]byte array in Go, the code currently sets the remaining items in Go to zero: https://github.com/fxamacker/cbor/blob/master/decode.go#L2391.

Now, this may be a design choice, but me trying to decode into a [32]byte kind of means I fully expect and want 32 bytes or a decode error. Silently padding with zeroes is IMO a potential security issue in certain systems because multiple different input data decodes to the same output struct.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions