]> git.baikalelectronics.ru Git - kernel.git/commit
crypto: atmel-aes - Fix IV handling when req->nbytes < ivsize
authorTudor Ambarus <tudor.ambarus@microchip.com>
Fri, 4 Oct 2019 08:55:37 +0000 (08:55 +0000)
committerHerbert Xu <herbert@gondor.apana.org.au>
Thu, 10 Oct 2019 12:42:45 +0000 (23:42 +1100)
commit2527356c780110c4bdefb70e6518ceb50c101147
tree71f2f32be1fcd98d73383d7ec9803e4d4da5ddd7
parentf799e973b06290395b2ee9e945998ab74649fc9e
crypto: atmel-aes - Fix IV handling when req->nbytes < ivsize

commit 1fb1296e8b59 ("crypto: cfb - add missing 'chunksize' property")
adds a test vector where the input length is smaller than the IV length
(the second test vector). This revealed a NULL pointer dereference in
the atmel-aes driver, that is caused by passing an incorrect offset in
scatterwalk_map_and_copy() when atmel_aes_complete() is called.

Do not save the IV in req->info of ablkcipher_request (or equivalently
req->iv of skcipher_request) when req->nbytes < ivsize, because the IV
will not be further used.

While touching the code, modify the type of ivsize from int to
unsigned int, to comply with the return type of
crypto_ablkcipher_ivsize().

Fixes: cb61a3bf82f0 ("crypto: atmel-aes - properly set IV after {en,de}crypt")
Cc: <stable@vger.kernel.org>
Signed-off-by: Tudor Ambarus <tudor.ambarus@microchip.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
drivers/crypto/atmel-aes.c