aboutsummaryrefslogtreecommitdiffstats
path: root/g10/gpg.h
diff options
context:
space:
mode:
authorWerner Koch <[email protected]>2025-02-21 11:16:17 +0000
committerWerner Koch <[email protected]>2025-02-21 11:17:46 +0000
commit48978ccb4e20866472ef18436a32744350a65158 (patch)
tree701624318831614937ebf91ff1685ef97749b429 /g10/gpg.h
parentgpg: Remove a signature check function wrapper. (diff)
downloadgnupg-48978ccb4e20866472ef18436a32744350a65158.tar.gz
gnupg-48978ccb4e20866472ef18436a32744350a65158.zip
gpg: Fix a verification DoS due to a malicious subkey in the keyring.
* g10/getkey.c (get_pubkey): Factor code out to ... (get_pubkey_bykid): new. Add feature to return the keyblock. (get_pubkey_for_sig): Add arg r_keyblock to return the used keyblock. Request a signing usage. (get_pubkeyblock_for_sig): Remove. (finish_lookup): Improve debug output. * g10/sig-check.c (check_signature): Add arg r_keyblock and pass it down. * g10/mainproc.c (do_check_sig): Ditto. (check_sig_and_print): Use the keyblock returned by do_check_sig to show further information instead of looking it up again with get_pubkeyblock_for_sig. Also re-check the signature after the import of an included keyblock. -- The problem here is that it is possible to import a key from someone who added a signature subkey from another public key and thus inhibits that a good signature good be verified. Such a malicious key signature subkey must have been created w/o the mandatory backsig which bind a signature subkey to its primary key. For encryption subkeys this is not an issue because the existence of a decryption private key is all you need to decrypt something and then it does not matter if the public subkey or its binding signature has been put below another primary key; in fact we do the latter for ADSKs. GnuPG-bug-id: 7527
Diffstat (limited to 'g10/gpg.h')
-rw-r--r--g10/gpg.h3
1 files changed, 2 insertions, 1 deletions
diff --git a/g10/gpg.h b/g10/gpg.h
index 7646aa3ee..117253884 100644
--- a/g10/gpg.h
+++ b/g10/gpg.h
@@ -73,7 +73,8 @@ struct dirmngr_local_s;
typedef struct dirmngr_local_s *dirmngr_local_t;
/* Object used to describe a keyblock node. */
-typedef struct kbnode_struct *KBNODE; /* Deprecated use kbnode_t. */typedef struct kbnode_struct *kbnode_t;
+typedef struct kbnode_struct *KBNODE; /* Deprecated use kbnode_t. */
+typedef struct kbnode_struct *kbnode_t;
/* The handle for keydb operations. */
typedef struct keydb_handle_s *KEYDB_HANDLE;