Skip to content

Commit 0300eb9

Browse files
tomato42t8m
authored andcommitted
pkcs12: verify that the pbmac1 key length is safe
Short mac keys (as short as 1 byte) can be used to probe the system under attack to accept a PKCS#12 file created by an attacker even if the attacker doesn't know the password used for MAC protection. Fixes CVE-2026-34181 (also update the reference to the PBMAC1 PKCS#12 RFC) Signed-off-by: Alicja Kario <hkario@redhat.com> Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 14:18:59 2026 (cherry picked from commit 84d226e59bbe4e72b73d855a1d6c8795130bc851)
1 parent f696c73 commit 0300eb9

4 files changed

Lines changed: 12 additions & 8 deletions

File tree

‎crypto/pkcs12/p12_mutl.c‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -147,12 +147,13 @@ static int PBMAC1_PBKDF2_HMAC(OSSL_LIB_CTX *ctx, const char *propq,
147147
}
148148
pbkdf2_salt = pbkdf2_param->salt->value.octet_string;
149149

150-
/* RFC 9579 specifies missing key length as invalid */
150+
/* RFC 9879 specifies missing key length as invalid */
151151
if (pbkdf2_param->keylength != NULL)
152152
keylen = ASN1_INTEGER_get(pbkdf2_param->keylength);
153-
if (keylen <= 0 || keylen > EVP_MAX_MD_SIZE) {
153+
/* RFC 9879 specifies too short key length as untrustworthy too */
154+
if (keylen < 20 || keylen > EVP_MAX_MD_SIZE) {
154155
ERR_raise_data(ERR_LIB_PKCS12, PKCS12_R_PARSE_ERROR,
155-
"Invalid Key length (%d is not in the range 1..64)", keylen);
156+
"Invalid Key length (%d is not in the range 20..64)", keylen);
156157
goto err;
157158
}
158159

‎test/recipes/80-test_pkcs12.t‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ $ENV{OPENSSL_WIN32_UTF8}=1;
5656

5757
my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0);
5858

59-
plan tests => 59 + ($no_fips ? 0 : 5);
59+
plan tests => 61 + ($no_fips ? 0 : 5);
6060

6161
# Test different PKCS#12 formats
6262
ok(run(test(["pkcs12_format_test"])), "test pkcs12 formats");
@@ -209,20 +209,23 @@ for my $instance (sort keys %pbmac1_tests) {
209209
}
210210
}
211211

212-
# Test pbmac1 pkcs12 good files, RFC 9579
213-
for my $file ("pbmac1_256_256.good.p12", "pbmac1_512_256.good.p12", "pbmac1_512_512.good.p12")
212+
# Test pbmac1 pkcs12 good files, RFC 9579, and one extra with shorter key
213+
# length
214+
for my $file ("pbmac1_256_256.good.p12", "pbmac1_512_256.good.p12",
215+
"pbmac1_512_512.good.p12",
216+
"pbmac1_256_256.good-shorter-key-len.p12")
214217
{
215218
my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file);
216219
ok(run(app(["openssl", "pkcs12", "-in", $path, "-password", "pass:1234", "-noenc"])),
217220
"test pbmac1 pkcs12 file $file");
218221
}
219222

220-
# Test pbmac1 pkcs12 bad files, RFC 9579 and CVE-2025-11187
223+
# Test pbmac1 pkcs12 bad files, RFC 9579, CVE-2025-11187 and CVE-2026-34181
221224
for my $file ("pbmac1_256_256.bad-iter.p12", "pbmac1_256_256.bad-salt.p12",
222225
"pbmac1_256_256.no-len.p12", "pbmac1_256_256.bad-len.p12",
223226
"pbmac1_256_256.bad-salt-type.p12", "pbmac1_256_256.negative-len.p12",
224227
"pbmac1_256_256.no-salt.p12", "pbmac1_256_256.very-big-len.p12",
225-
"pbmac1_256_256.zero-len.p12")
228+
"pbmac1_256_256.zero-len.p12", "pbmac1_256_256.bad-key-len.p12")
226229
{
227230
my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file);
228231
with({ exit_checker => sub { return shift == 1; } },
2.74 KB
Binary file not shown.
Binary file not shown.

0 commit comments

Comments
 (0)