Re: [PATCH] crypto: rsassa-pkcs1: use constant-time comparison for digest and signature verification

From: Eric Biggers

Date: Fri Jul 10 2026 - 17:40:07 EST


On Fri, Jul 10, 2026 at 07:29:33PM +0200, David C.C.M. Gall wrote:
> Replace memcmp() with crypto_memneq() for cryptographic digest and
> signature comparisons to prevent timing side-channel attacks.
>
> crypto/rsassa-pkcs1.c: RSA signature digest verification used memcmp
> which can leak valid prefix length via timing analysis, user data
> could reach the leaky comparison via the digest argument to verify.
>
> Assisted-by: gregkh_clanker_t1000
> Signed-off-by: David C.C.M. Gall <david.ccm.gall@xxxxxxxxxxxxxx>

While we should use crypto_memneq() on MACs, auth tags, and other secret
data, I don't think we should let it creep into domains where it is
clearly not needed, like public key signature verification.

- Eric