[openssl-commits] [openssl] OpenSSL_1_0_2-stable update

Rich Salz rsalz at openssl.org
Fri Sep 29 17:52:28 UTC 2017


The branch OpenSSL_1_0_2-stable has been updated
       via  f9cbf470180841966338db1f4c28d99ec4debec4 (commit)
      from  d9a38e859dfe30a112c421dc7b32821370efd805 (commit)


- Log -----------------------------------------------------------------
commit f9cbf470180841966338db1f4c28d99ec4debec4
Author: Samuel Weiser <samuel.weiser at iaik.tugraz.at>
Date:   Fri Sep 29 13:29:25 2017 +0200

    Added const-time flag to DSA key decoding to avoid potential leak of privkey
    
    Reviewed-by: Richard Levitte <levitte at openssl.org>
    Reviewed-by: Rich Salz <rsalz at openssl.org>
    (Merged from https://github.com/openssl/openssl/pull/4440)
    
    (cherry picked from commit 6364475a990449ef33fc270ac00472f7210220f2)

-----------------------------------------------------------------------

Summary of changes:
 crypto/dsa/dsa_ameth.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/crypto/dsa/dsa_ameth.c b/crypto/dsa/dsa_ameth.c
index c4fa105..aac2530 100644
--- a/crypto/dsa/dsa_ameth.c
+++ b/crypto/dsa/dsa_ameth.c
@@ -258,6 +258,7 @@ static int dsa_priv_decode(EVP_PKEY *pkey, PKCS8_PRIV_KEY_INFO *p8)
         goto dsaerr;
     }
 
+    BN_set_flags(dsa->priv_key, BN_FLG_CONSTTIME);
     if (!BN_mod_exp(dsa->pub_key, dsa->g, dsa->priv_key, dsa->p, ctx)) {
         DSAerr(DSA_F_DSA_PRIV_DECODE, DSA_R_BN_ERROR);
         goto dsaerr;


More information about the openssl-commits mailing list