No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Eric Biggers 7973dc9118 crypto: rsa-pkcs1pad - correctly get hash from source scatterlist
commit e316f7179be22912281ce6331d96d7c121fb2b17 upstream.

Commit c7381b0128 ("crypto: akcipher - new verify API for public key
algorithms") changed akcipher_alg::verify to take in both the signature
and the actual hash and do the signature verification, rather than just
return the hash expected by the signature as was the case before.  To do
this, it implemented a hack where the signature and hash are
concatenated with each other in one scatterlist.

Obviously, for this to work correctly, akcipher_alg::verify needs to
correctly extract the two items from the scatterlist it is given.
Unfortunately, it doesn't correctly extract the hash in the case where
the signature is longer than the RSA key size, as it assumes that the
signature's length is equal to the RSA key size.  This causes a prefix
of the hash, or even the entire hash, to be taken from the *signature*.

(Note, the case of a signature longer than the RSA key size should not
be allowed in the first place; a separate patch will fix that.)

It is unclear whether the resulting scheme has any useful security
properties.

Fix this by correctly extracting the hash from the scatterlist.

Fixes: c7381b0128 ("crypto: akcipher - new verify API for public key algorithms")
Cc: <stable@vger.kernel.org> # v5.2+
Reviewed-by: Vitaly Chikunov <vt@altlinux.org>
Signed-off-by: Eric Biggers <ebiggers@google.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-04-15 14:18:02 +02:00
arch ARM: dts: exynos: add missing HDMI supplies on SMDK5420 2022-04-15 14:18:02 +02:00
block block: don't merge across cgroup boundaries if blkcg is enabled 2022-04-15 14:18:01 +02:00
certs
crypto crypto: rsa-pkcs1pad - correctly get hash from source scatterlist 2022-04-15 14:18:02 +02:00
Documentation Documentation: update stable tree link 2022-04-15 14:17:58 +02:00
drivers thermal: int340x: Increase bitmap size 2022-04-15 14:18:02 +02:00
fs jffs2: fix memory leak in jffs2_scan_medium 2022-04-15 14:17:59 +02:00
include block: don't merge across cgroup boundaries if blkcg is enabled 2022-04-15 14:18:01 +02:00
init
ipc
kernel ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE 2022-04-15 14:17:58 +02:00
lib lib/raid6/test: fix multiple definition linking error 2022-04-15 14:18:02 +02:00
LICENSES
mm mm/kmemleak: reset tag when compare object pointer 2022-04-15 14:18:01 +02:00
net udp: call udp_encap_enable for v6 sockets when enabling encap 2022-04-15 14:18:01 +02:00
samples
scripts kconfig: fix failing to generate auto.conf 2022-02-23 12:00:01 +01:00
security KEYS: fix length validation in keyctl_pkey_params_get_2() 2022-04-15 14:17:58 +02:00
sound ALSA: hda/realtek: Fix audio regression on Mi Notebook Pro 2020 2022-04-15 14:18:00 +02:00
tools Revert "selftests/bpf: Add test for bpf_timer overwriting crash" 2022-03-23 09:12:08 +01:00
usr
virt KVM: arm64: Allow SMCCC_ARCH_WORKAROUND_3 to be discovered and migrated 2022-03-19 13:40:15 +01:00
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile Linux 5.4.188 2022-03-28 08:46:49 +02:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.