From: Jouni Malinen Date: Thu, 25 Apr 2019 15:52:34 +0000 (+0300) Subject: SAE: Use const_time_memcmp() for pwd_value >= prime comparison X-Git-Tag: hostap_2_9~341 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=8e14b030e558d23f65d761895c07089404e61cf1;p=thirdparty%2Fhostap.git SAE: Use const_time_memcmp() for pwd_value >= prime comparison This reduces timing and memory access pattern differences for an operation that could depend on the used password. Signed-off-by: Jouni Malinen --- diff --git a/src/common/sae.c b/src/common/sae.c index 5a50294a6..0d56e5505 100644 --- a/src/common/sae.c +++ b/src/common/sae.c @@ -317,7 +317,7 @@ static int sae_test_pwd_seed_ecc(struct sae_data *sae, const u8 *pwd_seed, wpa_hexdump_key(MSG_DEBUG, "SAE: pwd-value", pwd_value, sae->tmp->prime_len); - if (os_memcmp(pwd_value, prime, sae->tmp->prime_len) >= 0) + if (const_time_memcmp(pwd_value, prime, sae->tmp->prime_len) >= 0) return 0; x_cand = crypto_bignum_init_set(pwd_value, sae->tmp->prime_len);