]> git.ipfire.org Git - thirdparty/openssl.git/commit
cleanse stack variable in blake2[b|s] finalization
authorNeil Horman <nhorman@openssl.org>
Mon, 1 Jan 2024 14:25:03 +0000 (09:25 -0500)
committerNeil Horman <nhorman@openssl.org>
Wed, 3 Jan 2024 17:56:15 +0000 (12:56 -0500)
commitd64242fb13d98677a8aaf38adce09f9d92ede166
tree590a0755f7e54c9db1b4588208b7e180e8848a6b
parent2e2b1c69d60c8e2c7a0fd683e76463fb2e75d4e1
cleanse stack variable in blake2[b|s] finalization

If the output of a blake2[b|s] digest isn't a multipl of 8, then a stack
buffer is used to compute the final output, which is left un-zeroed
prior to return, allowing the potential leak of key data.  Ensure that,
if the stack variable is used, it gets cleared prior to return.

Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/23173)

(cherry picked from commit 8b9cf1bc2c3085b6e9493a057209ffd0bddf48a6)
providers/implementations/digests/blake2b_prov.c
providers/implementations/digests/blake2s_prov.c