From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id B278DC433EF for ; Thu, 21 Jul 2022 02:35:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References: Message-ID:Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=issevRUooF31R4uC+q+5fZLzgPKxbsqnHnV4vx/lobs=; b=ehVMHfgUO102Ts Kfh5h8l4tULBr+W06kftIKg+Oror5U4H0cTGXR3pPmOJYIaFPo1eBFE3n56CMXUkNRTGtcDGa5ZLB StcOPwx0qtPI8Yb5UdGQRb4aCnxaDKLouMI2cirnh8F0r/VYP46gnTfP6O/eE0DXq/MSNTq+2q8bM plQwY1zLJaNacYNeUYF0AqfAEpuwY5vUsAMWeOGFk2xjQbpYVzOtXpWhrgvKg3mn2ybX8of5n8Hlu 039BFTT8eVj0ck08VVSu14XnUrPubtUnBH4YZh3zKjkjgdmAkTuROwj+v4/ZfP9Nor5bApOPjaKaD Ee2R8GWA98J+zvFSW+AQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1oEM1S-00F7ch-63; Thu, 21 Jul 2022 02:34:42 +0000 Received: from sin.source.kernel.org ([2604:1380:40e1:4800::1]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1oEM1O-00F7aO-Oz for linux-arm-kernel@lists.infradead.org; Thu, 21 Jul 2022 02:34:40 +0000 Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sin.source.kernel.org (Postfix) with ESMTPS id 3B9C0CE1FE8; Thu, 21 Jul 2022 02:34:36 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4219CC3411E; Thu, 21 Jul 2022 02:34:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1658370874; bh=N4b5H7bsYZVAjTDde4MhRJd56uCFvrh0A1BWavAr9yg=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=LIpzdB0t8zEEhNAyqbmng2pzWyM98VK5wlPs07qs8d13rxScwoKT4KtCSmVmMxmDS dR+AVN+7OoI5cFrh7N5OREid4nLyETaJk7mV5Gwzj0oB5ib1x80iXIFsnjkEDdIBop tMIoeHovoF17w5X2CSgPAY2PjDRwJXisHijC/jJwglkNsv2HTM8uRzokVacdop2Nhm kpXqSaqZ8qmyS5ehfaCLfvKRRk7uyVjSttSUnV2QstB/mURZviIA+CaLCwVVyNs/Ou by+SeiIj0Err73ary+4ltfMQoVwfZ2eVHF/7inkPylgeWk1AoSjyriP51alOflcRSC 3jW1OLBovLADw== Date: Wed, 20 Jul 2022 19:34:18 -0700 From: Eric Biggers To: GUO Zihua Cc: linux-crypto@vger.kernel.org, linux-arm-kernel@lists.infradead.org, herbert@gondor.apana.org.au, davem@davemloft.net, catalin.marinas@arm.com, will@kernel.org Subject: Re: [PATCH v2] arm64/crypto: poly1305 fix a read out-of-bound Message-ID: References: <20220712075031.29061-1-guozihua@huawei.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20220712075031.29061-1-guozihua@huawei.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20220720_193439_029315_758E96ED X-CRM114-Status: GOOD ( 12.67 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Tue, Jul 12, 2022 at 03:50:31PM +0800, GUO Zihua wrote: > int init(void) > { > struct crypto_shash *tfm = NULL; > struct shash_desc *desc = NULL; > char *data = NULL; > > tfm = crypto_alloc_shash("poly1305", 0, 0); > desc = kmalloc(sizeof(*desc) + crypto_shash_descsize(tfm), GFP_KERNEL); > desc->tfm = tfm; > > data = kmalloc(POLY1305_KEY_SIZE - 1, GFP_KERNEL); > memcpy(data, test_data, POLY1305_KEY_SIZE - 1); > crypto_shash_update(desc, data, POLY1305_KEY_SIZE - 1); > crypto_shash_final(desc, data); > kfree(data); > return 0; > } This isn't actually a valid test case since it never calls crypto_shash_init(). So the behavior of this test is undefined both before and after this patch. The simplest way to write a correct test would be to use crypto_shash_tfm_digest(). Anyway, the bug is still real and this patch is still the correct fix, so it's good enough to add my reviewed-by: Reviewed-by: Eric Biggers - Eric _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel