sbsign: write unaligned signature size into WIN_CERTIFICATE header

The inclusion of padding bytes in the signature size can lead to the signature
being rejected by strict PKCS7 parsers. Meanwhile, according to [1], the parser
of the WIN_CERTIFICATE structure is expected to round up the value of dwLength
to an 8-byte multiple. This also matches the behaviour of the sbsign tool from
sbsigntools.

Fixes #42884

[1] https://learn.microsoft.com/en-us/windows/win32/debug/pe-format#the-attribute-certificate-table-image-only

Signed-off-by: Vsevolod Kozlov <zaba@mm.st>
(cherry picked from commit 93aadbf968)
This commit is contained in:
Vsevolod Kozlov
2026-07-06 13:40:53 +03:00
committed by Luca Boccassi
parent 775a9e171b
commit 706c4491ce

View File

@@ -659,7 +659,7 @@ static int verb_sign(int argc, char *argv[], uintptr_t _data, void *userdata) {
&(WIN_CERTIFICATE_HEADER) {
.wRevision = htole16(0x200),
.wCertificateType = htole16(0x0002), /* PKCS7 signedData */
.dwLength = htole32(ROUND_UP(certsz, 8)),
.dwLength = htole32(certsz),
},
sizeof(WIN_CERTIFICATE_HEADER),
end);