[crypto] Add missing padding length check in RSA decryption RSA PKCS#1 requires a minimum of eight non-zero padding bytes for encryption. This limit is currently enforced when encrypting but not validated when decrypting. The only existing code path that can currently lead to RSA decryption is CMS decryption, which can use RSA to decrypt the cipher key. With underlength PKCS#1 padding (and hence an overlength plaintext), the decrypted cipher key would be rejected by the immediately following call to cipher_setkey(). Add the missing padding length check as part of RSA decryption, and add a test case (imported from Project Wycheproof) to ensure that this check remains in place in future. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
boot from a web server via HTTP or HTTPS,
boot from an iSCSI, FCoE, or AoE SAN,
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.