20 Commits

Author SHA1 Message Date
fly2x
f123a1794e Add SM3 and SM4 support 2023-11-26 15:06:06 +08:00
zhoujing
9f3e384edd Support for building with clang 2023-10-10 21:26:09 +08:00
jiangfangjie 00559066
2e6a29de25 Fix CVE-2023--1018 and CVE-2023-1017 2023-03-08 10:41:10 +08:00
yezengruan
8fb30302f4 libtpms: update to version 0.9.5
Signed-off-by: yezengruan <yezengruan@huawei.com>
2023-02-03 18:56:46 +08:00
yezengruan
3bfb0ade75 fix CVE-2021-3623
tpm2: Reset TPM2B buffer sizes after test fails for valid buffer size
tpm2: Add maxSize parameter to TPM2B_Marshal for sanity checks
tpm2: Restore original value if unmarsalled value was illegal

Signed-off-by: yezengruan <yezengruan@huawei.com>
2022-05-18 15:59:45 +08:00
yezengruan
4565343e21 rename patch 0001-tpm2-CryptSym-fix-AES-output-IV.patch
renamed:
0001-tpm2-CryptSym-fix-AES-output-IV.patch
-> tpm2-CryptSym-fix-AES-output-IV.patch

Signed-off-by: yezengruan <yezengruan@huawei.com>
2022-05-18 15:40:12 +08:00
imxcc
68394a5bec fix bare word "debug" in spec
Signed-off-by: imxcc <xingchaochao@huawei.com>
2022-05-18 15:40:02 +08:00
jiangfangjie 00559066
d894603808 tpm2-Fix-issue-with-misaligned-address-when-marshall 2021-11-15 12:22:49 +08:00
jiangfangjie 00559066
f7aac383ce tpm2: Initialize a whole OBJECT before using it and NVMarshal: Handle index orderly RAM without 0-sized
terminating node

fix CVE-2021-3746

Signed-off-by: jiangfangjie 00559066 <jiangfangjie@huawei.com>
2021-11-10 17:37:04 +08:00
jiangfangjie 00559066
ceabec5e4b update libtpms.spec 2021-05-11 15:57:52 +08:00
jiangfangjie 00559066
49be9bc2ae fix the cve-2021-3505
Signed-off-by: jiangfangjie 00559066 <jiangfangjie@huawei.com>
2021-05-11 15:39:06 +08:00
jiangfangjie 00559066
1c62fb2410 update spec file
Signed-off-by: jiangfangjie 00559066 <jiangfangjie@huawei.com>
2021-04-07 10:38:52 +08:00
jiangfangjie 00559066
a1a4809abf tpm2: CryptSym: fix AES output IV
The TPM is supposed to provide the output IV in the ivInOut parameter in
CryptSymmetricEncrypt. In the case of using the openssl routines, the
output IV is missed, and the resulting output from the TPM is in the
input IV.

OpenSSL unfortunately does not export EVP_CIPHER_CTX_iv() until
tags/OpenSSL_1_1_0, so we have to fall back to the reference code for
previous OpenSSL versions.

Fixes: CVE-2021-3446
buglink:https://bugzilla.redhat.com/show_bug.cgi?id=1939664

Signed-off-by: William Roberts <william.c.roberts@intel.com>
Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
Signed-off-by: jiangfangjie 00559066 <jiangfangjie@huawei.com>
2021-04-06 18:19:30 +08:00
jiangfangjie
a5323d08cb update version to versionx
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-09-17 16:12:45 +08:00
jiangfangjie
2cb9c2ce66 update release
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-09-16 18:22:58 +08:00
jiangfangjie
f1dc1d5e42 update release
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-09-16 12:06:12 +08:00
jiangfangjie
9cefddfde8 update release
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-09-16 09:16:54 +08:00
jiangfangjie
e6e9493e17 update spec file and source file
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-09-15 20:04:36 +08:00
jiangfangjie
d396320548 update source0
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-09-14 20:18:42 +08:00
jiangfangjie
602e72bb02 init packet with version 0.7.3
Signed-off-by: jiangfangjie <jiangfangjie@huawei.com>
2020-08-21 13:09:43 +08:00