Skip to content

Fix SslStream handling of empty TLS handshake records - #134921

Merged
rzikm merged 1 commit into
dotnet:mainfrom
rzikm:rzikm/empty-tls-handshake-regression
Oct 6, 2026
Merged

rzikm merged 1 commit into
dotnet:mainfrom
rzikm:rzikm/empty-tls-handshake-regression

Conversation

@rzikm

@rzikm rzikm commented Sep 30, 2026

Copy link
Copy Markdown
Member

Recognizing exactly-five-byte TLS records exposed unchecked handshake-type reads in SslStream.ReceiveHandshakeFrameAsync. An empty handshake record (16 03 01 00 00) currently throws IndexOutOfRangeException during server authentication.

Validate the current record length before either ClientHello probe, retaining the protocol-specific TLS/SSLv2 offset. Empty handshake records now throw IOException immediately, without waiting for EOF or a sixth byte. Checking the record length rather than the buffered span also prevents trailing data from masking the malformed record. Five-byte frame recognition and application-data handling remain unchanged.

Regression coverage includes direct certificates, certificate/options callbacks, sync/async authentication, both handshake implementations, fragmented reads, trailing buffered data, and a peer that keeps its transport open. Tests use TLS 1.2 to exercise managed framing rather than Apple's separate Network Framework handshake path.

Validation

  • All 18 new regression cases fail against the rebuilt original library and pass with the fix.
  • Windows x64 library build and full local functional/unit suites pass: 5,410 passed, 40 existing platform/condition skips, zero failures.
  • The existing five-byte post-handshake framing regression still passes. Linux/macOS were not run locally.

Fixes: #134784

Resolves #134784

Note

This pull request was generated with GitHub Copilot.

Validate the current record length before both ClientHello probes and throw IOException for empty handshake records. Add regression coverage for certificate sources, sync and async authentication, fragmented input, read-ahead, and both handshake implementations.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 4 pipeline(s).
12 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

@wfurt wfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@rzikm
rzikm merged commit 383c70a into dotnet:main Oct 6, 2026
84 of 86 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Regression: IndexOutOfRangeException on a 5-byte zero-length handshake record

2 participants