From nobody Sat Jul 25 01:54:02 2026 Received: from mail-wr1-f51.google.com (mail-wr1-f51.google.com [209.85.221.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 582A03939AF for ; Mon, 20 Jul 2026 19:15:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784574931; cv=none; b=CdkdnfutkksoFmno+HK9oUjGGwIaSP589nv3w9Ty6x541Sv2RaUBBpssVskC0K5+dcf7IPQfsi15QTeDCtRzFcpHXc4Ohd/3FcdFuw50mX9b9JEcNkivsE5ZbKTu9Kfkvxhh5/HswTG4MZ3IBXSWMa+V0KkZGbatojiq62RA/g0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784574931; c=relaxed/simple; bh=xGOyn27kAb2aUQ2aktYzNNe4IoaFrQIOT8r1ok3Xtr0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=NM2DCniCVK2kiGvynqzrQvczldXKLwtjVe/tu3AgseAfr27znp6MiiUR98gtEViU61ZTB7svCBulMKjqZup6o/MyRazgZPZeyUPzLG+VKGurQIKxdy1LWwxrqEZeLXBa9YUZSRvyfzgp+pY7Y5eMgSENhWvjG3gmVlLMEXsZb0g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=boesQUmc; arc=none smtp.client-ip=209.85.221.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="boesQUmc" Received: by mail-wr1-f51.google.com with SMTP id ffacd0b85a97d-474560436c3so5379068f8f.0 for ; Mon, 20 Jul 2026 12:15:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1784574927; x=1785179727; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=5XDxWfj8KWZ9DgniRwAUL8R0m0HpW65KqxOgihYK1aU=; b=boesQUmcQve0LMfhp8Sq8RPEztONnkxYK9HAlpScNDaJZVI6NdiLf5cxWAozBZIvgB DpbTKWb/uSgIZxf7BsQDfbDxAfRq16VqzmPnhXrZWNzwZPSmPUXUO5gCVINPbhNPbVbo iUMPd4r+QKJV/JjOaSACnaOWS/9M8JgMFl6DKpmqVjjG0mqkKJ0NpNu72WllB9+EuoYF idCnNxdAv2bHOKs7ABSfxONA1R4/rFWwHGVdwKlHADqeT5ppGpmdEPIT3dYNYyzPLELp alKdijUvXcdFd9o8iAru8fXgfk1bFhrwdddU2VFskSfvypgzduhCAS1AeL9Cfv8c12pv GdvQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784574927; x=1785179727; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5XDxWfj8KWZ9DgniRwAUL8R0m0HpW65KqxOgihYK1aU=; b=nQ7VClAu6U6ufFoumZxFO7guPw1suKsXRrmGk0nYvus1dAXYa8Q1OGhCYFr7b23Nt3 F1zBfA0JlYR7oRnuhsHXVUl76YHJyC/TVZkKxU1eAdFv7+hNYuP/A8pOSc0A3qyYS2Hx NP7zkoRdYyOjuJ11F9fj5r3qcCXmfZ+ZV0A+HM/Hgu7jkUQoEZyycIjT6tno3em6GEQR ogX7cUzwEUn/aJDxExrqMDgd/urP/G7BPKQvAkbb7Zly8mKcxIgmqWf22E61mMkQMLz2 sV6KknxWuHj+76y5BGzbMYn5w1bFiN+C5VGhhjwrJQsji7626f6sq4Qqn3B9kptV5TJp ImaA== X-Forwarded-Encrypted: i=1; AHgh+RqY2lcV7vAKDk0YhpKZJmPaW4KBuBfYWjndUz2+j4d6LKGH6VzQg9nPRRGAFrHEfLE8dv/jlRRWb4g0sOQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yw/DGgWEQ12kUx8Q/figKHVgBXHsOIwJ7ZdQtFcLtpWWB5Bx25x TYOl7+kzRToXIlIRYVwOU724fsC97bbxS+MSi65Ha8puvDcpvyTNxV9XWkOKgGTBbpMP7ghCU4f 2tRA8Dg== X-Gm-Gg: AR+sD12Y1BtfoYxNF45VedirsdCRns2V+9ozWN91MoVJx8WbPN2jI1yy8r0bPKLxric ipTIEmXEOsXQbXCJoMrecgbO+S2DW07yrSaFPY2l0PRIhP/CAx8b4S/c7os5AWLk7rSYw5cUGY/ vGBfAu4sdG+rZ2pdvfjwXsdXrhK/LRSZfE/4HxsS9y93Ouj2yDNp4hAqiMsSqaIhNXkZeIhdsIt dsFzdfwmLIfRijaW/6Vg6h+YuC2wTnBJlGrGQ0kqnGnp4T5P4M8dzVzhi27CZfbtyzaNO7f1PIz pHWu+pZJ6TR9N7B5WZpjvvc1f3ScjouMqzKsgkz8YgweeXz+PBjOQUFTNxgG90uEDKpX9w0NUbM uf4g5FiB8RCSzIem5/uGdEq2UlU82r+NPraBbitqQp/I9NTCeSd9rf9BNh6/boouG52MJJjzKpV nbIB+TDOM4oJm/UYVF3c2pRU0obyRs+hRzZnA5cl/KSkXr7Ysqim3W2d4avO7PhlImAPvafL1B3 MVuADeNJ3vPNArFtloDuLth X-Received: by 2002:a5d:5d82:0:b0:47f:59b4:390c with SMTP id ffacd0b85a97d-47f62329496mr17832694f8f.50.1784574927315; Mon, 20 Jul 2026 12:15:27 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.14]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f63ee926dsm30211503f8f.35.2026.07.20.12.15.26 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 20 Jul 2026 12:15:26 -0700 (PDT) From: Doruk Tan Ozturk To: stable@vger.kernel.org Cc: herbert@gondor.apana.org.au, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, Doruk Tan Ozturk Subject: [PATCH 6.1/6.6/6.12.y] crypto: rsa-pkcs1pad: Don't WARN on an empty digest Date: Mon, 20 Jul 2026 21:15:25 +0200 Message-ID: <20260720191525.15450-1-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" KEYCTL_PKEY_VERIFY lets an unprivileged caller supply a zero-length digest (in_len =3D=3D 0). keyctl_pkey_params_get_2() accepts the zero length and the request reaches pkcs1pad_verify(), where the empty digest is rejected but only after being passed through WARN_ON(!digest_size). The warning is therefore directly user-triggerable, and on kernels built with panic_on_warn=3D1 an unprivileged process can panic the machine -- a local denial of service. Reproduced as UID 65534 in a setuid sandbox. Keep rejecting the invalid request with -EINVAL, but do not emit a warning for the user-controlled length. Mainline does not contain this code path; commit 1e562deacecc ("crypto: rsassa-pkcs1 - Migrate to sig_alg backend") removed pkcs1pad_verify() in v6.13-rc1. This is a minimal fix for the affected stable branches. It applies as-is to 6.1.y, 6.6.y and 6.12.y (identical pkcs1pad_verify); the 5.10.y/5.15.y form is sent as a separate patch due to the older req->dst_len spelling. Found by 0sec automated security-research tooling (https://0sec.ai). Fixes: c7381b012872 ("crypto: akcipher - new verify API for public key algo= rithms") Cc: stable@vger.kernel.org Assisted-by: 0sec:multi-model Signed-off-by: Doruk Tan Ozturk --- crypto/rsa-pkcs1pad.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crypto/rsa-pkcs1pad.c b/crypto/rsa-pkcs1pad.c index cd501195f34a..225fcc3377dd 100644 --- a/crypto/rsa-pkcs1pad.c +++ b/crypto/rsa-pkcs1pad.c @@ -557,7 +557,7 @@ static int pkcs1pad_verify(struct akcipher_request *req) const unsigned int digest_size =3D req->dst_len; int err; =20 - if (WARN_ON(req->dst) || WARN_ON(!digest_size) || + if (WARN_ON(req->dst) || !digest_size || !ctx->key_size || sig_size !=3D ctx->key_size) return -EINVAL; =20 --=20 2.43.0