[openssh-commits] [openssh] 02/04: upstream: Implement a maximum number of KDF rounds that will be

git+noreply at mindrot.org git+noreply at mindrot.org
Thu Oct 1 17:28:46 AEST 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit f938c78d490cb7556aa8ca1625e9b9bd1f963ed3
Author: djm at openbsd.org <djm at openbsd.org>
AuthorDate: Thu Oct 1 07:07:49 2026 +0000

    upstream: Implement a maximum number of KDF rounds that will be
    
    accepted when writing an OpenSSH-format private key or when loading one. This
    limit is set pretty high (1<<20), but ensures that a service that is passed a
    bad key with an ridiculously high number of rounds will _eventually_ complete
    parsing it.
    
    Also bump the default number of KDF rounds from 24 to 32 (this is a
    linear increase, not like bcrypt(3) which is exponential).
    
    Pointed out by Aris Adamantiadis
    
    OpenBSD-Commit-ID: 843ff37b066b2879f4579a784e42a3c9d22b2ddc
---
 sshkey.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/sshkey.c b/sshkey.c
index b5e63e028..dddfeb448 100644
--- a/sshkey.c
+++ b/sshkey.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: sshkey.c,v 1.164 2026/09/16 00:31:27 djm Exp $ */
+/* $OpenBSD: sshkey.c,v 1.165 2026/10/01 07:07:49 djm Exp $ */
 /*
  * Copyright (c) 2000, 2001 Markus Friedl.  All rights reserved.
  * Copyright (c) 2008 Alexander von Gernler.  All rights reserved.
@@ -72,7 +72,8 @@
 #define AUTH_MAGIC		"openssh-key-v1"
 #define SALT_LEN		16
 #define DEFAULT_CIPHERNAME	"aes256-ctr"
-#define	DEFAULT_ROUNDS		24
+#define	DEFAULT_ROUNDS		32
+#define	MAX_KDF_ROUNDS		(1<<20)
 
 /*
  * Constants relating to "shielding" support; protection of keys expected
@@ -2862,6 +2863,10 @@ sshkey_private_to_blob2(struct sshkey *prv, struct sshbuf *blob,
 
 	if (rounds <= 0)
 		rounds = DEFAULT_ROUNDS;
+	if (rounds > MAX_KDF_ROUNDS) {
+		r = SSH_ERR_INVALID_ARGUMENT;
+		goto out;
+	}
 	if (passphrase == NULL || !strlen(passphrase)) {
 		ciphername = "none";
 		kdfname = "none";
@@ -3126,6 +3131,10 @@ private2_decrypt(struct sshbuf *decoded, const char *passphrase,
 		if ((r = sshbuf_get_string(kdf, &salt, &slen)) != 0 ||
 		    (r = sshbuf_get_u32(kdf, &rounds)) != 0)
 			goto out;
+		if (rounds > MAX_KDF_ROUNDS) {
+			r = SSH_ERR_INVALID_FORMAT;
+			goto out;
+		}
 		if (bcrypt_pbkdf(passphrase, strlen(passphrase), salt, slen,
 		    key, keylen + ivlen, rounds) < 0) {
 			r = SSH_ERR_INVALID_FORMAT;

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list