CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]    2026/10/01 01:07:49

Modified files:
        usr.bin/ssh    : sshkey.c 

Log message:
Implement a maximum number of KDF rounds that will be accepted when
writing an OpenSSH-format private key or when loading one. This limit
is set pretty high (1<<20), but ensures that a service that is passed a
bad key with an ridiculously high number of rounds will _eventually_
complete parsing it.

Also bump the default number of KDF rounds from 24 to 32 (this is a
linear increase, not like bcrypt(3) which is exponential).

Pointed out by Aris Adamantiadis

Reply via email to