Fix side-channel in prime checking/generation

Signed-off-by: Manuel Pégourié-Gonnard <[email protected]>
This commit is contained in:
Manuel Pégourié-Gonnard
2026-05-22 00:35:55 +02:00
parent 72991252c8
commit 7a29052238
2 changed files with 52 additions and 8 deletions
@@ -0,0 +1,5 @@
Security
* Fix timing side channel in RSA key generation, prime generation and
primality testing, on platforms where division is not constant-time. At
this point this side channel is not known to be exploitable. Reported by
Bhargava Shastry, Ethereum Foundation.
+47 -8
View File
@@ -2059,6 +2059,25 @@ int mbedtls_mpi_inv_mod(mbedtls_mpi *X, const mbedtls_mpi *A, const mbedtls_mpi
#if defined(MBEDTLS_GENPRIME)
/* Product of small primes up to 997 included */
static const mbedtls_mpi_sint small_primes_limit = 997;
static const unsigned char small_primes_product_bin[] = {
0x05, 0xf0, 0x78, 0x61, 0x8e, 0x81, 0x21, 0xe1, 0xf0, 0xc5, 0x8a, 0xf3,
0xf5, 0xc7, 0xea, 0x54, 0xbf, 0x9d, 0x72, 0x52, 0xd3, 0x0b, 0xa9, 0xf7,
0xf2, 0xcb, 0x32, 0xc7, 0x69, 0x02, 0x6d, 0xe4, 0x48, 0xa9, 0x66, 0x72,
0x7b, 0x6a, 0x2f, 0xf9, 0x8f, 0x3a, 0xf2, 0x3d, 0x78, 0x6c, 0xf7, 0x03,
0xb4, 0xe6, 0x11, 0xac, 0xf6, 0xa8, 0xd9, 0xe8, 0x3b, 0x38, 0x7d, 0x1c,
0x20, 0xdf, 0xd8, 0xd5, 0x92, 0xe4, 0x0d, 0x19, 0x14, 0x35, 0xe3, 0xb5,
0x00, 0x68, 0x84, 0xce, 0x6d, 0x32, 0xbc, 0xa2, 0x0d, 0x62, 0x80, 0xe0,
0x17, 0xe1, 0x37, 0x85, 0x7a, 0xfc, 0x66, 0x1d, 0xf0, 0x45, 0x05, 0xfc,
0xa2, 0x31, 0xe5, 0x0c, 0x83, 0xa2, 0x46, 0x67, 0x43, 0x3a, 0x54, 0xf1,
0x4a, 0xe0, 0x57, 0x07, 0x34, 0xf4, 0x3e, 0x41, 0x39, 0x9d, 0x61, 0x8a,
0x96, 0x5d, 0xc9, 0x77, 0x8d, 0xe5, 0xe8, 0x18, 0x99, 0x1d, 0x8c, 0xc2,
0xad, 0xfb, 0x89, 0xbb, 0xfb, 0x2c, 0xba, 0x37, 0xdb, 0xbf, 0xd5, 0xa8,
0x30, 0xfb, 0x79, 0x35, 0xfc, 0x65, 0x61, 0xf5, 0xc0, 0xdf, 0xd6, 0x18,
0x9d, 0x7b, 0x9f, 0xa4, 0x20, 0xa4, 0x10, 0x2c, 0xa7, 0x95, 0xdf, 0xd0,
0xbb, 0x97, 0x6a, 0x13, 0x4b,
};
/* Gaps between primes, starting at 3. https://oeis.org/A001223 */
static const unsigned char small_prime_gaps[] = {
2, 2, 4, 2, 4, 2, 4, 6,
@@ -2097,26 +2116,46 @@ static const unsigned char small_prime_gaps[] = {
static int mpi_check_small_factors(const mbedtls_mpi *X)
{
int ret = 0;
size_t i;
mbedtls_mpi_uint r;
unsigned p = 3; /* The first odd prime */
mbedtls_mpi prod, g;
mbedtls_mpi_init(&prod);
mbedtls_mpi_init(&g);
if ((X->p[0] & 1) == 0) {
return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
}
for (i = 0; i < sizeof(small_prime_gaps); p += small_prime_gaps[i], i++) {
MBEDTLS_MPI_CHK(mbedtls_mpi_mod_int(&r, X, p));
if (r == 0) {
/* The GCD test below only works if X > small_primes_limit. */
if (mbedtls_mpi_cmp_int(X, small_primes_limit) <= 0) {
unsigned p = 3;
for (size_t i = 0; i < sizeof(small_prime_gaps); i++) {
if (mbedtls_mpi_cmp_int(X, p) == 0) {
return 1;
} else {
return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
}
p += small_prime_gaps[i];
}
return MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
}
MBEDTLS_MPI_CHK(mbedtls_mpi_read_binary(&prod, small_primes_product_bin,
sizeof(small_primes_product_bin)));
/* We can't directly use mbedtls_mpi_gcd_modinv_odd() because we don't know
* if X is larger than prod or not (prod is 1379 bits). So, use this generic
* wrapper - it does a bit more than what we need (handles even inputs as
* well, while we know our inputs are both odd), but that's OK. */
MBEDTLS_MPI_CHK(mbedtls_mpi_gcd(&g, &prod, X));
if (mbedtls_mpi_cmp_int(&g, 1) == 0) {
/* X is not divisible by a small prime */
ret = 0;
} else {
ret = MBEDTLS_ERR_MPI_NOT_ACCEPTABLE;
}
cleanup:
mbedtls_mpi_free(&prod);
mbedtls_mpi_free(&g);
return ret;
}