On Sat, Aug 22, 2026 at 09:27:04PM +0000, Jérémy Jean wrote:
> pkcs7_check_authattrs() only looks at the first SignerInfo when deciding
> whether rejection of authenticated attributes may be waived. For the
> remaining signers it checks only that authenticated attributes are either
> present on all signers or absent from all of them.
>
> This means an unmatched ML-DSA signer can be placed first, followed by a
> trusted RSA, ECDSA, or ECRDSA signer. Verification skips the unmatched
> signature and accepts the later trusted signer. The first signer still
> leaves the waiver enabled for the whole message, so the non-ML-DSA signer
> can use an exception intended only for ML-DSA.
>
> Check each SignerInfo's public-key algorithm before leaving the waiver
> enabled.
>
> Fixes: 91db696adea4 ("pkcs7: Allow authenticatedAttributes for ML-DSA")
> Assisted-by: Codex:gpt-5
> Signed-off-by: Jérémy Jean <[email protected]>
> ---
> crypto/asymmetric_keys/pkcs7_parser.c | 6 ++++++
> 1 file changed, 6 insertions(+)
Patch applied. Thanks.
--
Email: Herbert Xu <[email protected]>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt