Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ Add new entries under `Unreleased`; published release sections are history.

## Unreleased

- TLS refuses RSA keys with an even modulus (N-171).
- TLS no longer clears a record's packets after TCP has taken them (GHSA-8w5x-ff58-2fr2).
- HKDF-Extract rejects invalid buffer arguments (N-160).
- ECDHE key exchange and ECDSA signing fail when key generation fails (N-156).
Expand Down
9 changes: 9 additions & 0 deletions src/tls/ami_tls_crypto.c
Original file line number Diff line number Diff line change
Expand Up @@ -502,6 +502,15 @@ NX_CRYPTO_HUGE_NUMBER modulus_hn, exponent_hn, input_hn, output_hn, p_hn, q_hn
{
return(NX_CRYPTO_SIZE_ERROR);
}
/* An RSA modulus is odd. The certificate parser takes any bytes, and an
even one -- zero above all -- is refused by crypto68k and handed to the
vendored arithmetic, whose modulus scan walks below its buffer for zero
(N-171). Refused here, before any number is set up or computed, on
every path: public and CRT, accelerated and reference. */
if ((modulus[modulus_length - 1u] & 1u) == 0u)
{
return(NX_CRYPTO_INVALID_KEY);
}
/* Rounded to whole limbs as the carve is; the vendored operation's
comment has the arithmetic. */
{
Expand Down
19 changes: 19 additions & 0 deletions tests/fuzz/CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -606,6 +606,24 @@ if(CMAKE_SIZEOF_VOID_P EQUAL 4)
target_link_libraries(tls_rsa_bounds PRIVATE
fuzz_tls_ami fuzz_tls_nx_secure fuzz_tls_nx_crypto fuzz_tls_netx
fuzz_tls_ami fuzz_tls_nx_secure fuzz_tls_nx_crypto fuzz_tls_netx)
# N-171: ours refuses an even (above all a zero) modulus before any
# exponentiation. The four exponentiation entry points are wrapped so that
# an even modulus never reaches real arithmetic, with or without the check.
add_executable(tls_rsa_modulus_parity
tls_rsa_modulus_parity.c
fuzz_nxstub.c
fuzz_txstub.c)
target_include_directories(tls_rsa_modulus_parity PRIVATE ${_fuzz_tls_crypto_inc})
target_compile_definitions(tls_rsa_modulus_parity PRIVATE ${_fuzz_tls_def})
target_compile_options(tls_rsa_modulus_parity PRIVATE -UAMINETXDUO_IPV6 ${_fuzz_san} -Wall -Wextra)
target_link_options(tls_rsa_modulus_parity PRIVATE ${_fuzz_san}
-Wl,--wrap=c68k_huge_number_mont_power_modulus
-Wl,--wrap=c68k_crt_power_modulus
-Wl,--wrap=_nx_crypto_huge_number_mont_power_modulus
-Wl,--wrap=_nx_crypto_huge_number_crt_power_modulus)
target_link_libraries(tls_rsa_modulus_parity PRIVATE
fuzz_tls_ami fuzz_tls_nx_secure fuzz_tls_nx_crypto fuzz_tls_netx
fuzz_tls_ami fuzz_tls_nx_secure fuzz_tls_nx_crypto fuzz_tls_netx)

endif()

Expand Down Expand Up @@ -730,6 +748,7 @@ if(CMAKE_SIZEOF_VOID_P EQUAL 4)

add_test(NAME tls_rsa_key_regression COMMAND tls_rsa_key_regression)
add_test(NAME tls_rsa_bounds COMMAND tls_rsa_bounds)
add_test(NAME tls_rsa_modulus_parity COMMAND tls_rsa_modulus_parity)

# EIGHT STREAMS, NOT ONE, and the same number of mutations between them.
# Four was the first attempt and left this at 8.14 s of the ten-second
Expand Down
Loading
Loading