mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2025-08-05 19:35:48 +03:00
An initialization vector IV can have any number of bits between 1 and
2^64. So it should be filled to the lower 64-bit in the last step when computing ghash. Signed-off-by: openluopworld <wuhanluop@163.com>
This commit is contained in:
4
ChangeLog.d/bugfix-for-gcm-long-iv-size.txt
Normal file
4
ChangeLog.d/bugfix-for-gcm-long-iv-size.txt
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
Bugfix
|
||||||
|
* Fix a bug in mbedtls_gcm_starts() when bits of iv are longer than 2^32.
|
||||||
|
* Fix #4884.
|
||||||
|
|
@@ -257,6 +257,7 @@ int mbedtls_gcm_starts( mbedtls_gcm_context *ctx,
|
|||||||
size_t i;
|
size_t i;
|
||||||
const unsigned char *p;
|
const unsigned char *p;
|
||||||
size_t use_len, olen = 0;
|
size_t use_len, olen = 0;
|
||||||
|
uint64_t iv_bits;
|
||||||
|
|
||||||
GCM_VALIDATE_RET( ctx != NULL );
|
GCM_VALIDATE_RET( ctx != NULL );
|
||||||
GCM_VALIDATE_RET( iv != NULL );
|
GCM_VALIDATE_RET( iv != NULL );
|
||||||
@@ -286,7 +287,8 @@ int mbedtls_gcm_starts( mbedtls_gcm_context *ctx,
|
|||||||
else
|
else
|
||||||
{
|
{
|
||||||
memset( work_buf, 0x00, 16 );
|
memset( work_buf, 0x00, 16 );
|
||||||
MBEDTLS_PUT_UINT32_BE( iv_len * 8, work_buf, 12 );
|
iv_bits = (uint64_t)iv_len * 8;
|
||||||
|
MBEDTLS_PUT_UINT64_BE( iv_bits, work_buf, 8 );
|
||||||
|
|
||||||
p = iv;
|
p = iv;
|
||||||
while( iv_len > 0 )
|
while( iv_len > 0 )
|
||||||
|
Reference in New Issue
Block a user