[openssl-commits] [openssl] OpenSSL_1_0_2-stable update

Paul I. Dale pauli at openssl.org
Thu Nov 1 22:18:30 UTC 2018


The branch OpenSSL_1_0_2-stable has been updated
       via  880d1c76ed9916cddb97fe05fb4c144f0f6f1012 (commit)
      from  ebf65dbe1a67682d7e1f58db9c53ef737fb37f32 (commit)


- Log -----------------------------------------------------------------
commit 880d1c76ed9916cddb97fe05fb4c144f0f6f1012
Author: Pauli <paul.dale at oracle.com>
Date:   Thu Nov 1 08:44:11 2018 +1000

    Add a constant time flag to one of the bignums to avoid a timing leak.
    
    Reviewed-by: Tim Hudson <tjh at openssl.org>
    (Merged from https://github.com/openssl/openssl/pull/7549)
    
    (cherry picked from commit 00496b6423605391864fbbd1693f23631a1c5239)

-----------------------------------------------------------------------

Summary of changes:
 crypto/dsa/dsa_ossl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/crypto/dsa/dsa_ossl.c b/crypto/dsa/dsa_ossl.c
index 80daf60..c887c3c 100644
--- a/crypto/dsa/dsa_ossl.c
+++ b/crypto/dsa/dsa_ossl.c
@@ -295,9 +295,9 @@ static int dsa_sign_setup(DSA *dsa, BN_CTX *ctx_in, BIGNUM **kinvp,
 
     if ((dsa->flags & DSA_FLAG_NO_EXP_CONSTTIME) == 0) {
         BN_set_flags(&k, BN_FLG_CONSTTIME);
+        BN_set_flags(&l, BN_FLG_CONSTTIME);
     }
 
-
     if (dsa->flags & DSA_FLAG_CACHE_MONT_P) {
         if (!BN_MONT_CTX_set_locked(&dsa->method_mont_p,
                                     CRYPTO_LOCK_DSA, dsa->p, ctx))


More information about the openssl-commits mailing list