[openssl/openssl] 476166: Revised RSASVE degenerate ciphertext check.

"'openssl-machine' via openssl-commits" <[email protected]>
Newsgroups gmane.comp.encryption.openssl.cvs
Message-ID <openssl/openssl/push/refs/heads/openssl-4.0/[email protected]>
  Branch: refs/heads/openssl-4.0
  Home:   https://github.com/openssl/openssl
  Commit: 476166d0b6f0656141bccda98c9d29e74746ad67
      https://github.com/openssl/openssl/commit/476166d0b6f0656141bccda98c9d29e74746ad67
  Author: Viktor Dukhovni <[email protected]>
  Date:   2026-08-17 (Mon, 17 Aug 2026)

  Changed paths:
    M crypto/rsa/rsa_ossl.c
    M providers/implementations/kem/rsa_kem.c

  Log Message:
  -----------
  Revised RSASVE degenerate ciphertext check.

The additional ciphertext check is now applied in rsasve_recover() where it
belongs, and not in the underlying RSA primitives, where it remains conditional
defined(FIPS_MODULE).

Reviewed-by: Milan Broz <[email protected]>
Reviewed-by: Nikola Pajkovsky <[email protected]>
MergeDate: Mon Aug 17 13:58:56 2026
(Merged from https://github.com/openssl/openssl/pull/32314)



To unsubscribe from these emails, change your notification settings at https://github.com/openssl/openssl/settings/notifications

-- 
You received this message because you are subscribed to the Google Groups "openssl-commits" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-commits/openssl/openssl/push/refs/heads/openssl-4.0/03fcd0-476166%40github.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.