Skip to content

CVE-2026-21895: prime-is-1 panic fix (#624) not on master #690

Description

@vulgraph

Heads-up — running a backport-gap scanner across NVD and noticed the fix attached to CVE-2026-21895 / GHSA does not appear on master yet.

The upstream patch is 2926c91 — "fix: do not panic on a prime being 1 when loading a secret key (#624)" — which lands on a release branch / different lineage.

Against current master:

  • compare master...2926c91bef7c returns status=diverged, behind_by=161, ahead_by=8. The 8 ahead commits include the panic-fix on the source side; nothing equivalent shows on master.
  • Title search repo:RustCrypto/RSA "do not panic on a prime being 1 when loading a secret key" → 0 results in master's history.
  • Cargo.toml, Cargo.lock, src/key.rs are all present on master and the panic-prone code path in src/key.rs still matches the pre-fix shape.

If the master refactor obviated the bug a different way, please point me at the commit and I will close this. Otherwise a cherry-pick (or equivalent rewrite) of #624 onto master would resolve it.

I can open a draft PR if that is preferred over an issue — let me know.

— vulgraph backport scanner

Activity

  1. tarcieri commented on May 1, 2026

    @tarcieri
    Member

    The fix for the logic is there, however it looks like the regression test wasn't carried over and probably should be.

    As it were, the entire implementation diverged as we moved from num-bigint to crypto-bigint.

  2. vulgraph commented on May 1, 2026

    @vulgraph
    ContributorAuthor

    Spun up the test in #692 per your suggestion — single-file change to src/key.rs, no logic touch (the underlying fix in validate_private_key_parts is already on master). The port required two small adaptations vs upstream 2926c91bef's test: BigUint → BoxedUint, and routing through from_components_with_large_exponent (under #[cfg(feature = "hazmat")], like the existing small/large-exponent tests) since master's from_components now enforces the MIN_PUB_EXPONENT bound that would reject the original test's e = 185 before reaching the prime check. Happy to rework if you'd prefer a non-hazmat variant with realistic-size primes.

  3. added a commit that references this issue on May 1, 2026
  4. tarcieri commented on May 1, 2026

    @tarcieri
    Member

    Thanks! #692 is merged

  5. vulgraph commented on May 3, 2026

    @vulgraph
    ContributorAuthor

    Glad to see #692 landed, thanks @tarcieri. Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions