From 7e51c31aef2eab74d792a48ad3bb975764127122 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Manuel=20P=C3=A9gouri=C3=A9-Gonnard?= Date: Mon, 8 Jun 2026 11:14:53 +0200 Subject: [PATCH] rsa/psa: tune doc about RSA v1.5 decrypt usage MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Manuel Pégourié-Gonnard --- include/mbedtls/rsa.h | 7 ++++--- include/psa/crypto.h | 8 ++++++-- include/psa/crypto_values.h | 3 +-- 3 files changed, 11 insertions(+), 7 deletions(-) diff --git a/include/mbedtls/rsa.h b/include/mbedtls/rsa.h index d528b0a864..ac3a0f2c2c 100644 --- a/include/mbedtls/rsa.h +++ b/include/mbedtls/rsa.h @@ -737,12 +737,13 @@ int mbedtls_rsa_pkcs1_decrypt(mbedtls_rsa_context *ctx, * operation (RSAES-PKCS1-v1_5-DECRYPT). * * \warning This is an inherently dangerous function (CWE-242). Unless - * it is used in a side channel free and safe way (eg. - * implementing the TLS protocol as per 7.4.7.1 of RFC 5246), + * it is used in a side channel free and safe way, * the calling code is vulnerable. * Specifically, callers need to ensure an adversary cannot * distinguish between success, MBEDTLS_ERR_RSA_INVALID_PADDING - * and MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE via side channels. + * and MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE. Also, in the latter two + * cases, the values of the output bytes must be ignored, again + * without revealing whether that's the case. * * \note The output buffer length \c output_max_len should be * as large as the size \p ctx->len of \p ctx->N, for example, diff --git a/include/psa/crypto.h b/include/psa/crypto.h index 1a86af7261..7243ea1e5d 100644 --- a/include/psa/crypto.h +++ b/include/psa/crypto.h @@ -3127,9 +3127,13 @@ psa_status_t psa_asymmetric_encrypt(mbedtls_svc_key_id_t key, * * \warning When \p alg is #PSA_ALG_RSA_PKCS1V15_CRYPT, this is an * inherently dangerous function (CWE-242): unless it is used - * in a side channel free and safe way (eg. implementing the - * TLS protocol as per 7.4.7.1 of RFC 5246), the calling code + * in a side channel free and safe way, the calling code * is vulnerable. + * Specifically, callers need to ensure an adversary cannot + * distinguish between success, #PSA_ERROR_INVALID_PADDING and + * #PSA_ERROR_BUFFER_TOO_SMALL. Also, in the latter two cases, + * the values of the output bytes must be ignored, again + * without revealing whether that's the case. * * \param key Identifier of the key to use for the operation. * It must be an asymmetric key pair. It must diff --git a/include/psa/crypto_values.h b/include/psa/crypto_values.h index 1d678dbfc2..5e49e0d70e 100644 --- a/include/psa/crypto_values.h +++ b/include/psa/crypto_values.h @@ -1760,8 +1760,7 @@ * \warning Calling psa_asymmetric_decrypt() with this algorithm as a * parameter is considered an inherently dangerous function * (CWE-242). Unless it is used in a side channel free and safe - * way (eg. implementing the TLS protocol as per 7.4.7.1 of - * RFC 5246), the calling code is vulnerable. + * way, the calling code is vulnerable. * */ #define PSA_ALG_RSA_PKCS1V15_CRYPT ((psa_algorithm_t) 0x07000200)