Skip to content

Fix RSA constant-time padding and length checks - #710

Open
iamnoksio wants to merge 1 commit into
RustCrypto:masterfrom
iamnoksio:master
Open

iamnoksio wants to merge 1 commit into
RustCrypto:masterfrom
iamnoksio:master

Conversation

@iamnoksio

Copy link
Copy Markdown

This change removes variable-time padding behavior by writing into fixed-width buffers instead of slicing based on secret leading-zero counts. It also enforces the RFC 8017 ciphertext-length check before PKCS#1 v1.5 decryption and avoids variable-time Montgomery reduction on private-key paths. The patch adds regression tests covering padding edge cases, PKCS#1 v1.5 length rejection, and Montgomery reduction correctness.

This change removes variable-time padding behavior by writing into fixed-width buffers instead of slicing based on secret leading-zero counts. It also enforces the RFC 8017 ciphertext-length check before PKCS#1 v1.5 decryption and avoids variable-time Montgomery reduction on private-key paths. The patch adds regression tests covering padding edge cases, PKCS#1 v1.5 length rejection, and Montgomery reduction correctness.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant