parse_message_frame_with_tlvs treats the bytes after the base message as a TLV list, but TlvList::for_extensions filters out iterator errors. A trailing TLV whose declared length exceeds the remaining bytes therefore yields Ok((message, None)) and the base message is dispatched as if no extension data had been sent. TlvIter stops at the first error, so every later field is lost too. Malformed extension data from an authenticated peer fails open.
Fix: propagate the first TlvError from extract_tlv_fields as a ParserError so the frame is
rejected.
parse_message_frame_with_tlvstreats the bytes after the base message as a TLV list, butTlvList::for_extensionsfilters out iterator errors. A trailing TLV whose declared length exceeds the remaining bytes therefore yieldsOk((message, None))and the base message is dispatched as if no extension data had been sent.TlvIterstops at the first error, so every later field is lost too. Malformed extension data from an authenticated peer fails open.Fix: propagate the first
TlvErrorfromextract_tlv_fieldsas aParserErrorso the frame isrejected.