Skip to content

Commit a2ca7b2

Browse files
beldmitt8m
authored andcommitted
Enforce implicit rejection for CMS/PKCS#7 decryption
Drop the disablement of the implicit rejection for RSA PKCS#1 v1.5 decryption. Fixes CVE-2026-42768 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Alicja Kario <hkario@redhat.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 19:49:19 2026 (cherry picked from commit 33def545a0c173aec43891f24c3df4f7d2e4fd87)
1 parent a5b591e commit a2ca7b2

4 files changed

Lines changed: 11 additions & 17 deletions

File tree

‎crypto/cms/cms_env.c‎

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -644,13 +644,6 @@ static int cms_RecipientInfo_ktri_decrypt(CMS_ContentInfo *cms,
644644
if (!ossl_cms_env_asn1_ctrl(ri, 1))
645645
goto err;
646646

647-
if (EVP_PKEY_is_a(pkey, "RSA"))
648-
/* upper layer CMS code incorrectly assumes that a successful RSA
649-
* decryption means that the key matches ciphertext (which never
650-
* was the case, implicit rejection or not), so to make it work
651-
* disable implicit rejection for RSA keys */
652-
EVP_PKEY_CTX_ctrl_str(ktri->pctx, "rsa_pkcs1_implicit_rejection", "0");
653-
654647
if (evp_pkey_decrypt_alloc(ktri->pctx, &ek, &eklen, fixlen,
655648
ktri->encryptedKey->data,
656649
ktri->encryptedKey->length)

‎crypto/pkcs7/pk7_doit.c‎

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -203,13 +203,6 @@ static int pkcs7_decrypt_rinfo(unsigned char **pek, int *peklen,
203203
if (EVP_PKEY_decrypt_init(pctx) <= 0)
204204
goto err;
205205

206-
if (EVP_PKEY_is_a(pkey, "RSA"))
207-
/* upper layer pkcs7 code incorrectly assumes that a successful RSA
208-
* decryption means that the key matches ciphertext (which never
209-
* was the case, implicit rejection or not), so to make it work
210-
* disable implicit rejection for RSA keys */
211-
EVP_PKEY_CTX_ctrl_str(pctx, "rsa_pkcs1_implicit_rejection", "0");
212-
213206
ret = evp_pkey_decrypt_alloc(pctx, &ek, &eklen, fixlen,
214207
ri->enc_key->data, ri->enc_key->length);
215208
if (ret <= 0)

‎doc/man3/CMS_decrypt.pod‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ then the above behaviour is modified and an error B<is> returned if no
6868
recipient encrypted key can be decrypted B<without> generating a random
6969
content encryption key. Applications should use this flag with
7070
B<extreme caution> especially in automated gateways as it can leave them
71-
open to attack.
71+
open to attack. See L<EVP_PKEY_decrypt(3)> for more details.
7272

7373
It is possible to determine the correct recipient key by other means (for
7474
example looking them up in a database) and setting them in the CMS structure
@@ -103,7 +103,7 @@ mentioned in CMS_verify() also applies to CMS_decrypt().
103103

104104
=head1 SEE ALSO
105105

106-
L<ERR_get_error(3)>, L<CMS_encrypt(3)>
106+
L<ERR_get_error(3)>, L<CMS_encrypt(3)>, L<EVP_PKEY_decrypt(3)>
107107

108108
=head1 HISTORY
109109

‎doc/man3/PKCS7_decrypt.pod‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,14 @@ B<flags> is an optional set of flags.
2222
Although the recipients certificate is not needed to decrypt the data it is needed
2323
to locate the appropriate (of possible several) recipients in the PKCS#7 structure.
2424

25+
When RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt()
26+
will use implicit rejection mechanism. It always returns the result of RSA
27+
decryption of the symmetric key to avoid Marvin attack. This result is
28+
deterministic and can happen to match the symmetric cipher used for the content
29+
encryption. In case when the certificate is not provided, the last
30+
RecipientInfo producing the key looking valid will be used. It may cause
31+
getting garbage content on decryption.
32+
2533
The following flags can be passed in the B<flags> parameter.
2634

2735
If the B<PKCS7_TEXT> flag is set MIME headers for type B<text/plain> are deleted
@@ -40,7 +48,7 @@ be better if it could look up the correct key and certificate from a database.
4048

4149
=head1 SEE ALSO
4250

43-
L<ERR_get_error(3)>, L<PKCS7_encrypt(3)>
51+
L<ERR_get_error(3)>, L<PKCS7_encrypt(3)>, L<EVP_PKEY_decrypt(3)>
4452

4553
=head1 COPYRIGHT
4654

0 commit comments

Comments
 (0)