Skip to content

Fix CVE-2023-50981 in Rabin private key decoding - #1357

Open
Coralesoft wants to merge 1 commit into
weidai11:masterfrom
Coralesoft:fix/cve-2023-50981-rabin-bedec
Open

Coralesoft wants to merge 1 commit into
weidai11:masterfrom
Coralesoft:fix/cve-2023-50981-rabin-bedec

Conversation

@Coralesoft

Copy link
Copy Markdown
Contributor

Summary

Addresses the Rabin decode portion of CVE-2023-50981.

InvertibleRabinFunction::BERDecode checked m_p and m_q for primality with CRYPTOPP_ASSERT, which is compiled out in release builds. A non-prime m_p or m_q could then reach CalculateInverse and cause ModularSquareRoot to loop indefinitely.

This promotes the checks to runtime BERDecodeError throws at the decode boundary. CalculateInverse keeps its defensive asserts as a double-check.

What changed

  • Replaced the end-of-decode CRYPTOPP_ASSERT(IsPrime(...)) checks in InvertibleRabinFunction::BERDecode with runtime BERDecodeError checks.

The BER decoder for Rabin private keys checked m_p and m_q for primality
with CRYPTOPP_ASSERT, which is compiled out in release builds. A non-prime
m_p or m_q could then reach CalculateInverse and cause ModularSquareRoot
to loop indefinitely.

Promote the checks to runtime BERDecodeError throws. The decoded key
material contains integers, but it is not a valid Rabin private key.
CalculateInverse keeps its defensive CRYPTOPP_ASSERT checks as a double-check.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant