<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/CryptoPkg/Library/BaseCryptLib/Pk/CryptRsaBasic.c, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-05-29T03:12:15+00:00</updated>
<entry>
<title>CryptoPkg: Fix leaks and failure-path mutation of RSA-owned values</title>
<updated>2026-05-29T03:12:15+00:00</updated>
<author>
<name>Mingjie Shen</name>
<email>shen497@purdue.edu</email>
</author>
<published>2026-05-21T20:22:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=269d0a61949d3da385f9b95ffb887f5fbf86b489'/>
<id>urn:sha1:269d0a61949d3da385f9b95ffb887f5fbf86b489</id>
<content type='text'>
RsaSetKey passed RSA-internal BIGNUMs (returned by RSA_get0_key /
RSA_get0_factors / RSA_get0_crt_params as const) directly to BN_bin2bn,
which mutates its destination in place. This violates the OpenSSL API
contract and can leave RsaContext in a partially modified state on
failure paths: BN_bin2bn has already overwritten one of
n / e / d / p / q / dp / dq / qInv, the function then returns FALSE
on a subsequent BN_dup or RSA_set0_* failure, and the caller has no
indication that the RSA object was silently changed. The same paths
also leaked temporary BIGNUMs allocated by BN_bin2bn or BN_new.

This patch splits RsaSetKey into a small input-validating dispatcher
plus three static helpers (RsaSetKeyNED, RsaSetKeyFactors,
RsaSetKeyCrtParams), one per RSA_set0_* setter. Each helper:

  - Allocates a fresh BIGNUM for the slot being set via
    BN_bin2bn(BigNumber, BnSize, NULL); the NULL destination forces
    BN_bin2bn to allocate so no RSA-owned BIGNUM is mutated.
  - Reads the current RSA state via RSA_get0_* purely for inspection.
  - For slots not being set, passes NULL when RSA already has a value
    (preserves it) or supplies an empty BN_new() placeholder when
    RSA's slot is still NULL.
  - Atomically installs via RSA_set0_*, which takes ownership of every
    non-NULL argument on success and of none on failure.
  - Routes all exits through a single label that frees any locally
    held BIGNUM. Memory leaks in the early-return paths are fixed as
    a consequence.

The previous BN_dup calls are no longer needed and are removed.

Signed-off-by: Mingjie Shen &lt;shen497@purdue.edu&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix memory leak in RsaSetKey</title>
<updated>2025-05-25T10:43:43+00:00</updated>
<author>
<name>Baraneedharan Anbazhagan</name>
<email>anbazhagan@hp.com</email>
</author>
<published>2025-05-23T02:44:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=347877c1ee0922df868aad8b5de80795730cdc94'/>
<id>urn:sha1:347877c1ee0922df868aad8b5de80795730cdc94</id>
<content type='text'>
Memory allocated by BN_new calls isn't deallocated within RsaSetKey.

Signed-off-by: Anbazhagan Baraneedharan &lt;anbazhagan@hp.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Apply uncrustify changes</title>
<updated>2021-12-07T17:24:28+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2021-12-05T22:53:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=7c342378317039e632d9a1a5d4cf7c21aec8cb7a'/>
<id>urn:sha1:7c342378317039e632d9a1a5d4cf7c21aec8cb7a</id>
<content type='text'>
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3737

Apply uncrustify changes to .c/.h files in the CryptoPkg package

Cc: Andrew Fish &lt;afish@apple.com&gt;
Cc: Leif Lindholm &lt;leif@nuviainc.com&gt;
Cc: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
Reviewed-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Support for SHA384 &amp; SHA512 RSA signing schemes</title>
<updated>2020-01-08T06:57:44+00:00</updated>
<author>
<name>Pavana.K</name>
<email>pavana.k@intel.com</email>
</author>
<published>2020-01-02T20:30:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=c9d72628432126cbce58a48b440e4944baa4beab'/>
<id>urn:sha1:c9d72628432126cbce58a48b440e4944baa4beab</id>
<content type='text'>
BZ: https://bugzilla.tianocore.org/show_bug.cgi?id=2389

Currently RSA signing scheme support is available for MD5, SHA-1 or
SHA-256 algorithms.The fix is to extend this support for SHA384 and
SHA512.

Cc: Liming Gao &lt;liming.gao@intel.com&gt;
Cc: Jian J Wang &lt;jian.j.wang@intel.com&gt;
Cc: Bob Feng &lt;bob.c.feng@intel.com&gt;

Signed-off-by: Pavana.K &lt;pavana.k@intel.com&gt;
Reviewed-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Replace BSD License with BSD+Patent License</title>
<updated>2019-04-09T16:10:22+00:00</updated>
<author>
<name>Michael D Kinney</name>
<email>michael.d.kinney@intel.com</email>
</author>
<published>2019-04-03T23:03:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2009f6b4c5cbd7dda95a2594288405224173d239'/>
<id>urn:sha1:2009f6b4c5cbd7dda95a2594288405224173d239</id>
<content type='text'>
https://bugzilla.tianocore.org/show_bug.cgi?id=1373

Replace BSD 2-Clause License with BSD+Patent License.  This change is
based on the following emails:

  https://lists.01.org/pipermail/edk2-devel/2019-February/036260.html
  https://lists.01.org/pipermail/edk2-devel/2018-October/030385.html

RFCs with detailed process for the license change:

  V3: https://lists.01.org/pipermail/edk2-devel/2019-March/038116.html
  V2: https://lists.01.org/pipermail/edk2-devel/2019-March/037669.html
  V1: https://lists.01.org/pipermail/edk2-devel/2019-March/037500.html

Contributed-under: TianoCore Contribution Agreement 1.1
Signed-off-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Reviewed-by: Jian J Wang &lt;jian.j.wang@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Clean up source files</title>
<updated>2018-06-28T03:19:40+00:00</updated>
<author>
<name>Liming Gao</name>
<email>liming.gao@intel.com</email>
</author>
<published>2018-06-27T09:32:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=630f67ddfea296ccb59d7863796210e130eec67e'/>
<id>urn:sha1:630f67ddfea296ccb59d7863796210e130eec67e</id>
<content type='text'>
1. Do not use tab characters
2. No trailing white space in one line
3. All files must end with CRLF

Contributed-under: TianoCore Contribution Agreement 1.1
Signed-off-by: Liming Gao &lt;liming.gao@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Update PK Cipher Wrappers work with opaque objects.</title>
<updated>2017-03-29T08:18:32+00:00</updated>
<author>
<name>Qin Long</name>
<email>qin.long@intel.com</email>
</author>
<published>2017-03-21T14:58:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=f56b11d2cd4d878d66edfe1a0c606a6b60b2df5c'/>
<id>urn:sha1:f56b11d2cd4d878d66edfe1a0c606a6b60b2df5c</id>
<content type='text'>
OpenSSL-1.1.xx makes most data structures opaque.
This patch updates Public Key Cipher Wrapper implementations in
BaseCryptLib to use the accessor APIs for opaque object access.
The impacted interfaces includes RSA, DH, X509, PKCS7, etc.

Cc: Ting Ye &lt;ting.ye@intel.com&gt;
Cc: Laszlo Ersek &lt;lersek@redhat.com&gt;
Cc: Ard Biesheuvel &lt;ard.biesheuvel@linaro.org&gt;
Cc: Gary Lin &lt;glin@suse.com&gt;
Cc: Ronald Cron &lt;ronald.cron@arm.com&gt;
Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: Qin Long &lt;qin.long@intel.com&gt;
Reviewed-by: Ting Ye &lt;ting.ye@intel.com&gt;
Tested-by: Laszlo Ersek &lt;lersek@redhat.com&gt;
Tested-by: Gary Lin &lt;glin@suse.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Fix typos in comments</title>
<updated>2016-11-07T15:21:22+00:00</updated>
<author>
<name>Gary Lin</name>
<email>glin@suse.com</email>
</author>
<published>2016-10-19T07:01:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=2998af862469c6a05657e169d7def6f55420caad'/>
<id>urn:sha1:2998af862469c6a05657e169d7def6f55420caad</id>
<content type='text'>
- intialized -&gt; initialized
- componenet -&gt; component
- compoents -&gt; components
- FAlSE -&gt; FALSE
- responsiblity -&gt; responsibility
- validility -&gt; validity
- procudure -&gt; procedure
- pamameter -&gt; parameter
- randome -&gt; random
- buiild -&gt; build

Cc: Ting Ye &lt;ting.ye@intel.com&gt;
Cc: Qin Long &lt;qin.long@intel.com&gt;
Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: Gary Lin &lt;glin@suse.com&gt;
Reviewed-by: Qin Long &lt;qin.long@intel.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg/BaseCryptLib: Add missing OpenSSL includes</title>
<updated>2015-10-29T14:15:53+00:00</updated>
<author>
<name>David Woodhouse</name>
<email>David.Woodhouse@intel.com</email>
</author>
<published>2015-10-29T14:15:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=1cae0c83bbd88822076542e2715077ca2a8bcadb'/>
<id>urn:sha1:1cae0c83bbd88822076542e2715077ca2a8bcadb</id>
<content type='text'>
OpenSSL 1.1 has cleaned up its include files a little, and it will now
be necessary to directly include things like &lt;openssl/bn.h&gt; if we want
to use them, rather than assuming they are included indirectly from
other headers.

Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: David Woodhouse &lt;David.Woodhouse@intel.com&gt;
Tested-by: Laszlo Ersek &lt;lersek@redhat.com&gt;
Reviewed-by: Qin Long &lt;qin.long@intel.com&gt;

git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@18698 6f19259b-4bc3-4df7-8a09-765794883524
</content>
</entry>
<entry>
<title>The openssl API RSA_public_decrypt() and RSA_private_encrypt() are deprecated, use RSA_sign(), RSA_verify() instead.</title>
<updated>2013-04-23T01:52:17+00:00</updated>
<author>
<name>sfu5</name>
<email>sfu5@6f19259b-4bc3-4df7-8a09-765794883524</email>
</author>
<published>2013-04-23T01:52:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=86b5c3ee549bbdeefa72115c2b7ca7f6f625ebed'/>
<id>urn:sha1:86b5c3ee549bbdeefa72115c2b7ca7f6f625ebed</id>
<content type='text'>
Signed-off-by: Long Qin &lt; qin.long@intel.com &gt;
Reviewed-by: Ye Ting  &lt;ting.ye@intel.com&gt;
Reviewed-by: Dong Guo &lt;guo.dong@intel.com&gt;

git-svn-id: https://edk2.svn.sourceforge.net/svnroot/edk2/trunk/edk2@14309 6f19259b-4bc3-4df7-8a09-765794883524
</content>
</entry>
</feed>
