mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
UPSTREAM: crypto: essiv - Check ssize for decryption and in-place encryption
[ Upstream commit 6bb73db6948c2de23e407fe1b7ef94bf02b7529f ]
Move the ssize check to the start in essiv_aead_crypt so that
it's also checked for decryption and in-place encryption.
Bug: 451939108
Reported-by: Muhammad Alifa Ramdhan <ramdhan@starlabs.sg>
Fixes: be1eb7f78a ("crypto: essiv - create wrapper template for ESSIV generation")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit dc4c854a5e7453c465fa73b153eba4ef2a240abe)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I675993b4640189861f0fe8a3f61a89c2f3821f19
This commit is contained in:
parent
f332d6bb33
commit
0a4bf073fa
1 changed files with 6 additions and 8 deletions
|
|
@ -203,9 +203,14 @@ static int essiv_aead_crypt(struct aead_request *req, bool enc)
|
|||
const struct essiv_tfm_ctx *tctx = crypto_aead_ctx(tfm);
|
||||
struct essiv_aead_request_ctx *rctx = aead_request_ctx(req);
|
||||
struct aead_request *subreq = &rctx->aead_req;
|
||||
int ivsize = crypto_aead_ivsize(tfm);
|
||||
int ssize = req->assoclen - ivsize;
|
||||
struct scatterlist *src = req->src;
|
||||
int err;
|
||||
|
||||
if (ssize < 0)
|
||||
return -EINVAL;
|
||||
|
||||
crypto_cipher_encrypt_one(tctx->essiv_cipher, req->iv, req->iv);
|
||||
|
||||
/*
|
||||
|
|
@ -215,19 +220,12 @@ static int essiv_aead_crypt(struct aead_request *req, bool enc)
|
|||
*/
|
||||
rctx->assoc = NULL;
|
||||
if (req->src == req->dst || !enc) {
|
||||
scatterwalk_map_and_copy(req->iv, req->dst,
|
||||
req->assoclen - crypto_aead_ivsize(tfm),
|
||||
crypto_aead_ivsize(tfm), 1);
|
||||
scatterwalk_map_and_copy(req->iv, req->dst, ssize, ivsize, 1);
|
||||
} else {
|
||||
u8 *iv = (u8 *)aead_request_ctx(req) + tctx->ivoffset;
|
||||
int ivsize = crypto_aead_ivsize(tfm);
|
||||
int ssize = req->assoclen - ivsize;
|
||||
struct scatterlist *sg;
|
||||
int nents;
|
||||
|
||||
if (ssize < 0)
|
||||
return -EINVAL;
|
||||
|
||||
nents = sg_nents_for_len(req->src, ssize);
|
||||
if (nents < 0)
|
||||
return -EINVAL;
|
||||
|
|
|
|||
Loading…
Reference in a new issue