Sync pki to chromium ce4bc9571462aa298d79b591df9d997323cf5157

Bug: chromium:1322914
Change-Id: Ic5a1349013bcfb279e5fee9f9838c63558d663b7
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/63025
Auto-Submit: Bob Beck <bbe@google.com>
Commit-Queue: Bob Beck <bbe@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
diff --git a/fuzz/parse_crldp_fuzzer.cc b/fuzz/parse_crldp_fuzzer.cc
new file mode 100644
index 0000000..ebf3ba2
--- /dev/null
+++ b/fuzz/parse_crldp_fuzzer.cc
@@ -0,0 +1,24 @@
+// Copyright 2023 The Chromium Authors
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#include <stddef.h>
+#include <stdint.h>
+
+#include "../pki/parse_certificate.h"
+#include "../pki/input.h"
+#include <openssl/base.h>
+
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
+  std::vector<bssl::ParsedDistributionPoint> distribution_points;
+
+  bool success = ParseCrlDistributionPoints(bssl::der::Input(data, size),
+                                            &distribution_points);
+
+  if (success) {
+    // A valid CRLDistributionPoints must have at least 1 element.
+    BSSL_CHECK(!distribution_points.empty());
+  }
+
+  return 0;
+}