[openssl] master update

Dr. Paul Dale pauli at openssl.org
Wed Apr 8 00:57:46 UTC 2020


The branch master has been updated
       via  069165d10646a22000c596095cc04d43bbf1f807 (commit)
      from  96218269f4c2da82f143727fb7697d572c190bc5 (commit)


- Log -----------------------------------------------------------------
commit 069165d10646a22000c596095cc04d43bbf1f807
Author: Patrick Steuer <patrick.steuer at de.ibm.com>
Date:   Sat Feb 22 01:20:09 2020 +0100

    AES CTR-DRGB: do not leak timing information
    
    Signed-off-by: Patrick Steuer <patrick.steuer at de.ibm.com>
    
    Reviewed-by: Tomas Mraz <tmraz at fedoraproject.org>
    Reviewed-by: Paul Dale <paul.dale at oracle.com>
    (Merged from https://github.com/openssl/openssl/pull/11147)

-----------------------------------------------------------------------

Summary of changes:
 crypto/rand/drbg_ctr.c | 22 +++++++++-------------
 1 file changed, 9 insertions(+), 13 deletions(-)

diff --git a/crypto/rand/drbg_ctr.c b/crypto/rand/drbg_ctr.c
index 85b204d3be..52559fab09 100644
--- a/crypto/rand/drbg_ctr.c
+++ b/crypto/rand/drbg_ctr.c
@@ -21,19 +21,15 @@
  */
 static void inc_128(RAND_DRBG_CTR *ctr)
 {
-    int i;
-    unsigned char c;
-    unsigned char *p = &ctr->V[15];
-
-    for (i = 0; i < 16; i++, p--) {
-        c = *p;
-        c++;
-        *p = c;
-        if (c != 0) {
-            /* If we didn't wrap around, we're done. */
-            break;
-        }
-    }
+    unsigned char *p = &ctr->V[0];
+    u32 n = 16, c = 1;
+
+    do {
+        --n;
+        c += p[n];
+        p[n] = (u8)c;
+        c >>= 8;
+    } while (n);
 }
 
 static void ctr_XOR(RAND_DRBG_CTR *ctr, const unsigned char *in, size_t inlen)


More information about the openssl-commits mailing list