On Sat, Aug 22, 2026 at 09:27:04PM +0000, Jérémy Jean wrote:
> pkcs7_check_authattrs() only looks at the first SignerInfo when deciding
> whether rejection of authenticated attributes may be waived.  For the
> remaining signers it checks only that authenticated attributes are either
> present on all signers or absent from all of them.
> 
> This means an unmatched ML-DSA signer can be placed first, followed by a
> trusted RSA, ECDSA, or ECRDSA signer.  Verification skips the unmatched
> signature and accepts the later trusted signer.  The first signer still
> leaves the waiver enabled for the whole message, so the non-ML-DSA signer
> can use an exception intended only for ML-DSA.
> 
> Check each SignerInfo's public-key algorithm before leaving the waiver
> enabled.
> 
> Fixes: 91db696adea4 ("pkcs7: Allow authenticatedAttributes for ML-DSA")
> Assisted-by: Codex:gpt-5
> Signed-off-by: Jérémy Jean <[email protected]>
> ---
>  crypto/asymmetric_keys/pkcs7_parser.c | 6 ++++++
>  1 file changed, 6 insertions(+)

Patch applied.  Thanks.
-- 
Email: Herbert Xu <[email protected]>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Reply via email to