Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

RSAKeyFormatHelper does not reject nonsense RSAPrivateKey versions

Open Beginner friendly
#134,659 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
84/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
csharp

Research direction

Start with the validation at RSAKeyFormatHelper.Pkcs1.cs lines 23-25 and inspect the signed Version definition in PrivateKeyInfoAsn.xml.cs. Trace the existing RSA private-key decoding path, add coverage for negative versions, and verify that an RSAPrivateKey with any negative version is rejected rather than treated as version 0.

Written by the indexing model from the issue text.

Description

area-System.Security untriaged
Description

If an RSAPrivateKey has a version of -1 it decodes successfully and is treated as 0.

https://github.com/dotnet/runtime/blob/0598ca0a45c1f29be94f889a1fc6e9b30c40ea64/src/libraries/Common/src/System/Security/Cryptography/RSAKeyFormatHelper.Pkcs1.cs#L23-L25

Version is a signed integer, so it can contain negative values:

https://github.com/dotnet/runtime/blob/0598ca0a45c1f29be94f889a1fc6e9b30c40ea64/src/libraries/Common/src/System/Security/Cryptography/Asn1/PrivateKeyInfoAsn.xml.cs#L15

Reproduction Steps

Construct an RSAPrivateKey with a version of -1, or any other negative number.

Expected behavior

The RSAPrivateKey should be rejected.

Actual behavior

The RSAPrivateKey version is treated as 0.

Regression?

No

Known Workarounds

No response

Configuration

No response

Other information

RFC 8017 and RFC 3447 define version as

Version ::= INTEGER { two-prime(0), multi(1) }
               (CONSTRAINED BY
               {-- version must be multi if otherPrimeInfos present --}

Since .NET does not support multi-prime values for key imports, the version check should probably just be != 0.

Dominant language
C#
Stars
18.3k
Forks
5.6k
Avg merge
2d 17h
Merged PRs (30d)
615

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dotnet/runtime

All issues in dotnet/runtime

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.