[openssl-commits] [openssl] OpenSSL_1_1_1-stable update

Paul I. Dale pauli at openssl.org
Thu Nov 1 22:14:49 UTC 2018

The branch OpenSSL_1_1_1-stable has been updated
       via  6039651c43944cf4633483a74c2ef3a6b8c0c6c0 (commit)
      from  222b0a8e1a43e67c8d65fd325828d8860ed2d348 (commit)

- Log -----------------------------------------------------------------
commit 6039651c43944cf4633483a74c2ef3a6b8c0c6c0
Author: Pauli <paul.dale at oracle.com>
Date:   Thu Nov 1 08:44:11 2018 +1000

    Add a constant time flag to one of the bignums to avoid a timing leak.
    Reviewed-by: Tim Hudson <tjh at openssl.org>
    (Merged from https://github.com/openssl/openssl/pull/7549)
    (cherry picked from commit 00496b6423605391864fbbd1693f23631a1c5239)


Summary of changes:
 crypto/dsa/dsa_ossl.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/crypto/dsa/dsa_ossl.c b/crypto/dsa/dsa_ossl.c
index 2dd2d74..7a0b087 100644
--- a/crypto/dsa/dsa_ossl.c
+++ b/crypto/dsa/dsa_ossl.c
@@ -223,6 +223,7 @@ static int dsa_sign_setup(DSA *dsa, BN_CTX *ctx_in,
     } while (BN_is_zero(k));
     BN_set_flags(k, BN_FLG_CONSTTIME);
+    BN_set_flags(l, BN_FLG_CONSTTIME);
     if (dsa->flags & DSA_FLAG_CACHE_MONT_P) {
         if (!BN_MONT_CTX_set_locked(&dsa->method_mont_p,

More information about the openssl-commits mailing list