ssh: limit bcrypt KDF rounds in OpenSSH private key decryption passphraseProtectedOpenSSHKey decodes the bcrypt round count from the key file and passes it directly to bcrypt_pbkdf.Key, whose running time is linear in that count. Files specifying very large round values cause the decryption to consume excessive CPU time: a uint32 maximum is several months of work on commodity hardware. Cap the accepted round count at 2048 (128x the default of 16, a few seconds of CPU on a modern core). OpenSSH itself does not impose an upper bound, but accepting arbitrary values turns key loading into a resource-exhaustion footgun for any code that processes files supplied by end users. This issue was found during a security audit by NCC Group Cryptography Services, sponsored by Teleport, and was assessed and is being fixed as a non-security bug. Change-Id: I01112bdf1b484ae4fab5dc8841d1a272f112df74 Reviewed-on: https://go-review.googlesource.com/c/crypto/+/782422 Reviewed-by: David Chase <drchase@google.com> Reviewed-by: Filippo Valsorda <filippo@golang.org> Reviewed-by: Junyang Shao <shaojunyang@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
This repository holds supplementary Go cryptography packages.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.
The git repository is https://go.googlesource.com/crypto.
The main issue tracker for the crypto repository is located at https://go.dev/issues. Prefix your issue with “x/crypto:” in the subject line, so it is easy to find.
Note that contributions to the cryptography package receive additional scrutiny due to their sensitive nature. Patches may take longer than normal to receive feedback.