diff --git a/ChangeLog b/ChangeLog
index 705dfd95164c48d919537b52fa41fc1a5a5d9cf7..2b7dac88005eda3b6139217ab01235b392f03e22 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -13,6 +13,9 @@
 
 2018-11-08  Simo Sorce	  <simo@redhat.com>
 
+	* pkcs1-sec-decrypt.c (_pkcs1_sec_decrypt_variable): New private
+	function. Variable size version for backwards compatibility.
+
 	* testsuite/rsa-sec-decrypt-test.c: Adds more tests.
 
 	* rsa-sec-decrypt.c (rsa_sec_decrypt): New function.
diff --git a/pkcs1-sec-decrypt.c b/pkcs1-sec-decrypt.c
index 802fb3e7bbff08d7de1ebbcc68499478618cc1e6..722044b00c7fa991a6fdd2fcf8845f8f8738caee 100644
--- a/pkcs1-sec-decrypt.c
+++ b/pkcs1-sec-decrypt.c
@@ -135,10 +135,10 @@ _pkcs1_sec_decrypt_variable(size_t *length, uint8_t *message,
   offset -= shift;
   /* In this loop, the bits of the 'offset' variable are used as shifting
    * conditions, starting from the least significant bit. The end result is
-   * that the buffer is shifted left eaxctly 'offset' bytes. */
+   * that the buffer is shifted left exactly 'offset' bytes. */
   for (shift = 1; shift < buflen; shift <<= 1, offset >>= 1)
     {
-      /* 'ok' is both the a least significant bit mask and a condition */
+      /* 'ok' is both a least significant bit mask and a condition */
       cnd_memcpy(offset & ok, message, message + shift, buflen - shift);
     }