You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
43 lines
1.1 KiB
43 lines
1.1 KiB
From 38d600147331d36e74174ebbd4008b63188b321b Mon Sep 17 00:00:00 2001 |
|
From: Andy Polyakov <appro@openssl.org> |
|
Date: Thu, 17 Aug 2017 21:08:57 +0200 |
|
Subject: [PATCH] bn/asm/x86_64-mont5.pl: fix carry bug in bn_sqrx8x_internal. |
|
|
|
Credit to OSS-Fuzz for finding this. |
|
|
|
CVE-2017-3736 |
|
|
|
Reviewed-by: Rich Salz <rsalz@openssl.org> |
|
--- |
|
crypto/bn/asm/x86_64-mont5.pl | 12 ++++++++++-- |
|
1 file changed, 10 insertions(+), 2 deletions(-) |
|
|
|
diff --git a/crypto/bn/asm/x86_64-mont5.pl b/crypto/bn/asm/x86_64-mont5.pl |
|
index 3bb0cdf..42178e4 100755 |
|
--- a/crypto/bn/asm/x86_64-mont5.pl |
|
+++ b/crypto/bn/asm/x86_64-mont5.pl |
|
@@ -3090,11 +3090,19 @@ $code.=<<___; |
|
|
|
.align 32 |
|
.Lsqrx8x_break: |
|
- sub 16+8(%rsp),%r8 # consume last carry |
|
+ xor $zero,$zero |
|
+ sub 16+8(%rsp),%rbx # mov 16(%rsp),%cf |
|
+ adcx $zero,%r8 |
|
mov 24+8(%rsp),$carry # initial $tptr, borrow $carry |
|
+ adcx $zero,%r9 |
|
mov 0*8($aptr),%rdx # a[8], modulo-scheduled |
|
- xor %ebp,%ebp # xor $zero,$zero |
|
+ adc \$0,%r10 |
|
mov %r8,0*8($tptr) |
|
+ adc \$0,%r11 |
|
+ adc \$0,%r12 |
|
+ adc \$0,%r13 |
|
+ adc \$0,%r14 |
|
+ adc \$0,%r15 |
|
cmp $carry,$tptr # cf=0, of=0 |
|
je .Lsqrx8x_outer_loop |
|
|
|
-- |
|
2.9.5 |
|
|
|
|