The rsa crate is open to the Marvin timing attack #252

Open
opened 2026-10-02 19:03:39 -04:00 by Salastil · 0 comments
Owner

From a memory-safety audit of nobilis on 2 October 2026: its own code has two unsafe blocks (both sound libc calls in main.rs), so what follows is about the code it depends on. Advisories were checked against the OSV/RustSec database for every crate in Cargo.lock, and each one traced to whether it is actually compiled in.

rsa 0.9.10 - RUSTSEC-2023-0071, Marvin Attack: potential key recovery through timing side channels. There is no fixed release of the rsa crate.

Where it is used, and why the risk is low:

  • nobilis, backend/discord/mod.rs: RSA-OAEP for Discord's QR sign-in (remote auth). A fresh key is generated for each sign-in and lives for one handshake with Discord's own gateway over TLS; Marvin needs many timed decryptions of attacker-chosen ciphertexts under the same key.
  • arti (tor-key-forge, tor-hscrypto, ssh-key-fork-arti) for Tor key handling.

Worth tracking rather than fixing now: move to a constant-time implementation when the crate ships one (or aws-lc-rs's RSA, already in the tree through rustls), and recheck if RSA is ever used with a long-lived key.

From a memory-safety audit of nobilis on 2 October 2026: its own code has two `unsafe` blocks (both sound libc calls in `main.rs`), so what follows is about the code it depends on. Advisories were checked against the OSV/RustSec database for every crate in `Cargo.lock`, and each one traced to whether it is actually compiled in. **rsa 0.9.10** - RUSTSEC-2023-0071, *Marvin Attack: potential key recovery through timing side channels*. There is no fixed release of the `rsa` crate. Where it is used, and why the risk is low: - **nobilis**, `backend/discord/mod.rs`: RSA-OAEP for Discord's QR sign-in (remote auth). A fresh key is generated for each sign-in and lives for one handshake with Discord's own gateway over TLS; Marvin needs many timed decryptions of attacker-chosen ciphertexts under the same key. - **arti** (`tor-key-forge`, `tor-hscrypto`, `ssh-key-fork-arti`) for Tor key handling. Worth tracking rather than fixing now: move to a constant-time implementation when the crate ships one (or `aws-lc-rs`'s RSA, already in the tree through rustls), and recheck if RSA is ever used with a long-lived key.
Salastil added this to the v1.0 milestone 2026-10-02 19:03:39 -04:00
Salastil added the buglow priorityCVE labels 2026-10-02 19:03:39 -04:00
Salastil removed this from the v1.0 milestone 2026-10-03 21:31:10 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Salastil/moho#252