target/arm: Fix PAuth sbox functions
Fix CVE-2020-10702 bug Signed-off-by: zhanghailiang <zhang.zhanghailiang@huawei.com>
This commit is contained in:
parent
a5d2ec2d8e
commit
f261f58550
49
target-arm-Fix-PAuth-sbox-functions.patch
Normal file
49
target-arm-Fix-PAuth-sbox-functions.patch
Normal file
@ -0,0 +1,49 @@
|
||||
From a7149fc18020c3d432c31838069dcfcb745299bf Mon Sep 17 00:00:00 2001
|
||||
From: zhanghailiang <zhang.zhanghailiang@huawei.com>
|
||||
Date: Sat, 20 Jun 2020 12:01:30 +0800
|
||||
Subject: [PATCH] target/arm: Fix PAuth sbox functions
|
||||
|
||||
In the PAC computation, sbox was applied over wrong bits.
|
||||
As this is a 4-bit sbox, bit index should be incremented by 4 instead of 16.
|
||||
|
||||
Test vector from QARMA paper (https://eprint.iacr.org/2016/444.pdf) was
|
||||
used to verify one computation of the pauth_computepac() function which
|
||||
uses sbox2.
|
||||
|
||||
Launchpad: https://bugs.launchpad.net/bugs/1859713
|
||||
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
|
||||
Signed-off-by: Vincent DEHORS <vincent.dehors@smile.fr>
|
||||
Signed-off-by: Adrien GRASSEIN <adrien.grassein@smile.fr>
|
||||
Message-id: 20200116230809.19078-2-richard.henderson@linaro.org
|
||||
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
|
||||
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
|
||||
Signed-off-by: zhanghailiang <zhang.zhanghailiang@huawei.com>
|
||||
---
|
||||
target/arm/pauth_helper.c | 4 ++--
|
||||
1 file changed, 2 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/target/arm/pauth_helper.c b/target/arm/pauth_helper.c
|
||||
index d3194f20..0a5f41e1 100644
|
||||
--- a/target/arm/pauth_helper.c
|
||||
+++ b/target/arm/pauth_helper.c
|
||||
@@ -89,7 +89,7 @@ static uint64_t pac_sub(uint64_t i)
|
||||
uint64_t o = 0;
|
||||
int b;
|
||||
|
||||
- for (b = 0; b < 64; b += 16) {
|
||||
+ for (b = 0; b < 64; b += 4) {
|
||||
o |= (uint64_t)sub[(i >> b) & 0xf] << b;
|
||||
}
|
||||
return o;
|
||||
@@ -104,7 +104,7 @@ static uint64_t pac_inv_sub(uint64_t i)
|
||||
uint64_t o = 0;
|
||||
int b;
|
||||
|
||||
- for (b = 0; b < 64; b += 16) {
|
||||
+ for (b = 0; b < 64; b += 4) {
|
||||
o |= (uint64_t)inv_sub[(i >> b) & 0xf] << b;
|
||||
}
|
||||
return o;
|
||||
--
|
||||
2.23.0
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user