CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2026/10/01 01:07:49
Modified files:
usr.bin/ssh : sshkey.c
Log message:
Implement a maximum number of KDF rounds that will be accepted when
writing an OpenSSH-format private key or when loading one. This limit
is set pretty high (1<<20), but ensures that a service that is passed a
bad key with an ridiculously high number of rounds will _eventually_
complete parsing it.
Also bump the default number of KDF rounds from 24 to 32 (this is a
linear increase, not like bcrypt(3) which is exponential).
Pointed out by Aris Adamantiadis