| CVE: CVE-2018-0734 |
| |
| Upstream-Status: Backport |
| |
| Signed-off-by: Kai Kang <kai.kang@windriver.com> |
| |
| From 43e6a58d4991a451daf4891ff05a48735df871ac Mon Sep 17 00:00:00 2001 |
| From: Pauli <paul.dale@oracle.com> |
| Date: Mon, 29 Oct 2018 08:24:22 +1000 |
| Subject: [PATCH] Merge DSA reallocation timing fix CVE-2018-0734. |
| |
| Reviewed-by: Richard Levitte <levitte@openssl.org> |
| (Merged from https://github.com/openssl/openssl/pull/7513) |
| --- |
| crypto/dsa/dsa_ossl.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/crypto/dsa/dsa_ossl.c b/crypto/dsa/dsa_ossl.c |
| index 2dcfedeeee..100e269268 100644 |
| --- a/crypto/dsa/dsa_ossl.c |
| +++ b/crypto/dsa/dsa_ossl.c |
| @@ -279,7 +279,7 @@ static int dsa_sign_setup(DSA *dsa, BN_CTX *ctx_in, BIGNUM **kinvp, |
| goto err; |
| |
| /* Preallocate space */ |
| - q_bits = BN_num_bits(dsa->q); |
| + q_bits = BN_num_bits(dsa->q) + sizeof(dsa->q->d[0]) * 16; |
| if (!BN_set_bit(&k, q_bits) |
| || !BN_set_bit(&l, q_bits) |
| || !BN_set_bit(&m, q_bits)) |
| -- |
| 2.17.0 |
| |