David Howells
cc25b994ac
X.509: Fix the time validation [ver #2 ]
...
This fixes CVE-2015-5327. It affects kernels from 4.3-rc1 onwards.
Fix the X.509 time validation to use month number-1 when looking up the
number of days in that month. Also put the month number validation before
doing the lookup so as not to risk overrunning the array.
This can be tested by doing the following:
cat <<EOF | openssl x509 -outform DER | keyctl padd asymmetric "" @s
-----BEGIN CERTIFICATE-----
MIIDbjCCAlagAwIBAgIJAN/lUld+VR4hMA0GCSqGSIb3DQEBCwUAMCkxETAPBgNV
BAoMCGxvY2FsLWNhMRQwEgYDVQQDDAtzaWduaW5nIGtleTAeFw0xNTA5MDEyMTMw
MThaFw0xNjA4MzEyMTMwMThaMCkxETAPBgNVBAoMCGxvY2FsLWNhMRQwEgYDVQQD
DAtzaWduaW5nIGtleTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANrn
crcMfMeG67nagX4+m02Xk9rkmsMKI5XTUxbikROe7GSUVJ27sPVPZp4mgzoWlvhh
jfK8CC/qhEhwep8Pgg4EJZyWOjhZb7R97ckGvLIoUC6IO3FC2ZnR7WtmWDgo2Jcj
VlXwJdHhKU1VZwulh81O61N8IBKqz2r/kDhIWiicUCUkI/Do/RMRfKAoDBcSh86m
gOeIAGfq62vbiZhVsX5dOE8Oo2TK5weAvwUIOR7OuGBl5AqwFlPnXQolewiHzKry
THg9e44HfzG4Mi6wUvcJxVaQT1h5SrKD779Z5+8+wf1JLaooetcEUArvWyuxCU59
qxA4lsTjBwl4cmEki+cCAwEAAaOBmDCBlTAMBgNVHRMEBTADAQH/MAsGA1UdDwQE
AwIHgDAdBgNVHQ4EFgQUyND/eKUis7ep/hXMJ8iZMdUhI+IwWQYDVR0jBFIwUIAU
yND/eKUis7ep/hXMJ8iZMdUhI+KhLaQrMCkxETAPBgNVBAoMCGxvY2FsLWNhMRQw
EgYDVQQDDAtzaWduaW5nIGtleYIJAN/lUld+VR4hMA0GCSqGSIb3DQEBCwUAA4IB
AQAMqm1N1yD5pimUELLhT5eO2lRdGUfTozljRxc7e2QT3RLk2TtGhg65JFFN6eml
XS58AEPVcAsSLDlR6WpOpOLB2giM0+fV/eYFHHmh22yqTJl4YgkdUwyzPdCHNOZL
hmSKeY9xliHb6PNrNWWtZwhYYvRaO2DX4GXOMR0Oa2O4vaYu6/qGlZOZv3U6qZLY
wwHEJSrqeBDyMuwN+eANHpoSpiBzD77S4e+7hUDJnql4j6xzJ65+nWJ89fCrQypR
4sN5R3aGeIh3QAQUIKpHilwek0CtEaYERgc5m+jGyKSc1rezJW62hWRTaitOc+d5
G5hh+9YpnYcxQHEKnZ7rFNKJ
-----END CERTIFICATE-----
EOF
If it works, it emit a key ID; if it fails, it should give a bad message
error.
Reported-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Signed-off-by: David Howells <dhowells@redhat.com>
Tested-by: Mimi Zohar <zohar@linux.vnet.ibm.com>
Acked-by: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: James Morris <james.l.morris@oracle.com>
2015-11-12 21:17:15 +11:00
..
asymmetric_keys
X.509: Fix the time validation [ver #2 ]
2015-11-12 21:17:15 +11:00
async_tx
md/raid5: activate raid6 rmw feature
2015-04-22 08:00:42 +10:00
.gitignore
crypto: rsa - add .gitignore for crypto/*.-asn1.[ch] files
2015-06-25 23:29:24 +08:00
842.c
crypto: 842 - change 842 alg to use software
2015-05-11 15:06:43 +08:00
ablk_helper.c
crypto: cryptd - process CRYPTO_ALG_INTERNAL
2015-03-31 21:21:04 +08:00
ablkcipher.c
crypto: api - Only abort operations on fatal signal
2015-10-20 21:59:25 +08:00
aead.c
crypto: aead - Remove CRYPTO_ALG_AEAD_NEW flag
2015-08-17 16:53:53 +08:00
aes_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
af_alg.c
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-next
2015-06-24 16:49:49 -07:00
ahash.c
crypto: ahash - ensure statesize is non-zero
2015-10-13 22:28:10 +08:00
akcipher.c
crypto: akcipher - Don't #include crypto/public_key.h as the contents aren't used
2015-10-20 22:14:01 +08:00
algapi.c
crypto: api - Only abort operations on fatal signal
2015-10-20 21:59:25 +08:00
algboss.c
crypto: algboss - Remove reference to nivaead
2015-08-17 16:53:41 +08:00
algif_aead.c
crypto: algif_aead - fix for multiple operations on AF_ALG sockets
2015-08-25 21:13:20 +08:00
algif_hash.c
crypto: algif_hash - Only export and import on sockets with data
2015-11-02 17:48:30 +08:00
algif_rng.c
crypto: algif_rng - Remove obsolete const-removal cast
2015-04-22 09:30:21 +08:00
algif_skcipher.c
crypto: replace scatterwalk_sg_chain with sg_chain
2015-08-17 08:12:54 -06:00
ansi_cprng.c
crypto: ansi_cprng - Convert to new rng interface
2015-04-22 09:30:18 +08:00
anubis.c
api.c
crypto: api - Only abort operations on fatal signal
2015-10-20 21:59:25 +08:00
arc4.c
authenc.c
crypto: aead - Remove CRYPTO_ALG_AEAD_NEW flag
2015-08-17 16:53:53 +08:00
authencesn.c
crypto: aead - Remove CRYPTO_ALG_AEAD_NEW flag
2015-08-17 16:53:53 +08:00
blkcipher.c
crypto: blkcipher - Include crypto/aead.h
2015-05-13 10:31:34 +08:00
blowfish_common.c
blowfish_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
camellia_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
cast5_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
cast6_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
cast_common.c
cbc.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
ccm.c
crypto: replace scatterwalk_sg_chain with sg_chain
2015-08-17 08:12:54 -06:00
chacha20_generic.c
crypto: chacha20 - Export common ChaCha20 helpers
2015-07-17 21:20:21 +08:00
chacha20poly1305.c
crypto: aead - Remove CRYPTO_ALG_AEAD_NEW flag
2015-08-17 16:53:53 +08:00
chainiv.c
crypto: chainiv - Offer normal cipher functionality without RNG
2015-06-22 15:49:28 +08:00
cipher.c
cmac.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
compress.c
crc32.c
crc32c_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
crct10dif_common.c
crct10dif_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
cryptd.c
crypto: aead - Remove CRYPTO_ALG_AEAD_NEW flag
2015-08-17 16:53:53 +08:00
crypto_null.c
crypto: null - Add default null skcipher
2015-05-22 11:25:55 +08:00
crypto_user.c
crypto: api - Only abort operations on fatal signal
2015-10-20 21:59:25 +08:00
crypto_wq.c
ctr.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
cts.c
crypto: cts - Weed out non-CBC algorithms
2015-01-20 14:44:15 +11:00
deflate.c
des_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
drbg.c
crypto: drbg - report backend_cra_name when allocation fails
2015-06-11 21:55:28 +08:00
ecb.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
echainiv.c
crypto: echainiv - Use generic geniv init/exit helpers
2015-08-17 16:53:46 +08:00
eseqiv.c
crypto: eseqiv - Offer normal cipher functionality without RNG
2015-06-22 15:49:28 +08:00
fcrypt.c
fips.c
crypto: fips - Move fips_enabled sysctl into fips.c
2015-04-23 14:18:09 +08:00
gcm.c
Merge branch 'for-4.3/sg' of git://git.kernel.dk/linux-block
2015-09-02 13:22:38 -07:00
gf128mul.c
ghash-generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
hash_info.c
hmac.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
internal.h
crypto: api - Remove linux/fips.h from internal.h
2015-04-23 14:18:10 +08:00
jitterentropy-kcapi.c
crypto: jitterentropy - remove unnecessary information from a comment
2015-10-14 22:23:16 +08:00
jitterentropy.c
crypto: jitterentropy - Delete unnecessary checks before the function call "kzfree"
2015-06-25 23:18:33 +08:00
Kconfig
crypto: keywrap - enable compilation
2015-10-15 21:05:06 +08:00
keywrap.c
crypto: keywrap - add key wrapping block chaining mode
2015-10-15 21:05:04 +08:00
khazad.c
lrw.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
lz4.c
lz4hc.c
lzo.c
Makefile
crypto: keywrap - enable compilation
2015-10-15 21:05:06 +08:00
mcryptd.c
crypto: mcryptd - process CRYPTO_ALG_INTERNAL
2015-03-31 21:21:13 +08:00
md4.c
md5.c
crypto: md5 - use md5 IV MD5_HX instead of their raw value
2015-05-18 12:20:18 +08:00
memneq.c
michael_mic.c
pcbc.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
pcompress.c
crypto: pcomp - Use crypto_alg_extsize helper
2015-04-21 10:19:55 +08:00
pcrypt.c
crypto: aead - Remove CRYPTO_ALG_AEAD_NEW flag
2015-08-17 16:53:53 +08:00
poly1305_generic.c
crypto: poly1305 - Export common Poly1305 helpers
2015-07-17 21:20:26 +08:00
proc.c
crypto: fips - Move fips_enabled sysctl into fips.c
2015-04-23 14:18:09 +08:00
ripemd.h
rmd128.c
rmd160.c
rmd256.c
rmd320.c
rng.c
crypto: rng - Do not free default RNG when it becomes unused
2015-06-22 15:49:18 +08:00
rsa.c
crypto: akcipher - Changes to asymmetric key API
2015-10-14 22:23:16 +08:00
rsa_helper.c
crypto: akcipher - Changes to asymmetric key API
2015-10-14 22:23:16 +08:00
rsaprivkey.asn1
crypto: akcipher - Changes to asymmetric key API
2015-10-14 22:23:16 +08:00
rsapubkey.asn1
crypto: akcipher - Changes to asymmetric key API
2015-10-14 22:23:16 +08:00
salsa20_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
scatterwalk.c
crypto: scatterwalk - Hide PageSlab call to optimise away flush_dcache_page
2015-06-03 10:51:25 +08:00
seed.c
seqiv.c
crypto: seqiv - Use generic geniv init/exit helpers
2015-08-17 16:53:46 +08:00
serpent_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
sha1_generic.c
crypto: sha1-generic - move to generic glue implementation
2015-04-10 21:39:40 +08:00
sha256_generic.c
crypto: sha256-generic - move to generic glue implementation
2015-04-10 21:39:41 +08:00
sha512_generic.c
crypto: sha512-generic - move to generic glue implementation
2015-04-10 21:39:41 +08:00
shash.c
crypto: shash - Use crypto_alg_extsize helper
2015-04-21 10:19:54 +08:00
skcipher.c
crypto: skcipher - blkcipher and ablkcipher should it be static
2015-10-01 21:56:57 +08:00
tcrypt.c
crypto: tcrypt - avoid mapping from module image addresses
2015-09-21 22:00:36 +08:00
tcrypt.h
crypto: tcrypt - Add ChaCha20/Poly1305 speed tests
2015-07-17 21:20:20 +08:00
tea.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
testmgr.c
crypto: keywrap - add testmgr support
2015-10-15 21:05:08 +08:00
testmgr.h
crypto: keywrap - add testmgr support
2015-10-15 21:05:08 +08:00
tgr192.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
twofish_common.c
twofish_generic.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
vmac.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
wp512.c
crypto: add missing crypto module aliases
2015-01-13 22:29:11 +11:00
xcbc.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
xor.c
xts.c
crypto: include crypto- module prefix in template
2014-11-26 20:06:30 +08:00
zlib.c
crypto: pcomp - Constify (de)compression parameters
2015-05-01 11:16:37 +08:00