RSAKeyFormatHelper does not reject nonsense RSAPrivateKey versions
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- csharp
- Domain
- cryptography, security
Research direction
Start with the validation at RSAKeyFormatHelper.Pkcs1.cs lines 23-25 and inspect the signed Version definition in PrivateKeyInfoAsn.xml.cs. Trace the existing RSA private-key decoding path, add coverage for negative versions, and verify that an RSAPrivateKey with any negative version is rejected rather than treated as version 0.
Written by the indexing model from the issue text.
Description
Description
If an RSAPrivateKey has a version of -1 it decodes successfully and is treated as 0.
Version is a signed integer, so it can contain negative values:
Reproduction Steps
Construct an RSAPrivateKey with a version of -1, or any other negative number.
Expected behavior
The RSAPrivateKey should be rejected.
Actual behavior
The RSAPrivateKey version is treated as 0.
Regression?
No
Known Workarounds
No response
Configuration
No response
Other information
RFC 8017 and RFC 3447 define version as
Version ::= INTEGER { two-prime(0), multi(1) }
(CONSTRAINED BY
{-- version must be multi if otherPrimeInfos present --}
Since .NET does not support multi-prime values for key imports, the version check should probably just be != 0.
- Dominant language
- C#
- Stars
- 18.3k
- Forks
- 5.6k
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 615
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/runtime
-
area-Infrastructure-coreclr os-ios os-maccatalyst os-tvos untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
dotnet/runtime#134766 · 3 comments ·
Maintainers usually reply within 1 day
-
area-System.Linq untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
dotnet/runtime#134736 · 3 comments ·
Maintainers usually reply within 1 day
-
area-System.Numerics.Tensors untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
dotnet/runtime#134691 · 2 comments ·
Maintainers usually reply within 1 day
-
area-System.Threading blocking-clean-ci Known Build Error untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
dotnet/runtime#134679 · 4 comments ·
Maintainers usually reply within 1 day
-
ARM64: conditional compare rejects negative immediates the emitter can already encode as `ccmn`Openarea-CodeGen-coreclr performance
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
dotnet/runtime#134663 · 1 comment ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
NethermindEth/nethermind#14012 ·
Maintainers usually reply within 1 day
-
dependencies Status: Triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
json-schema-org/website#2518 ·
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
builtbybel/Flyoobe#498 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
builtbybel/CrapFixer#112 ·