diff options
author | jsing <> | 2022-05-07 07:47:24 +0000 |
---|---|---|
committer | jsing <> | 2022-05-07 07:47:24 +0000 |
commit | e1722600a0a7e0b3d60235d3052a2203c73e84b0 (patch) | |
tree | fea88905a338e173a2ff4c9ba0fb67b479b0ff6c /src/lib/libssl/man/SSL_CTX_set_tmp_rsa_callback.3 | |
parent | c84564af0c5d26256cd2cf25c38c41332c5c08a0 (diff) | |
download | openbsd-e1722600a0a7e0b3d60235d3052a2203c73e84b0.tar.gz openbsd-e1722600a0a7e0b3d60235d3052a2203c73e84b0.tar.bz2 openbsd-e1722600a0a7e0b3d60235d3052a2203c73e84b0.zip |
Avoid strict aliasing violations in BN_nist_mod_*()
The optimised code path switches from processing data via unsigned long to
processing data via unsigned int, which requires type punning. This is
currently attempted via a union (for one case), however this fails since
a pointer to a union member is passed to another function (these unions
were added to "fix strict-aliasing compiler warning" - it would seem the
warnings stopped but the undefined behaviour remained). The second case
does not use a union and simply casts from one type to another.
Undefined behaviour is currently triggered when compiling with clang 14
using -03 and -fstrict-aliasing, while disabling assembly (in order to use
this C code). The resulting binary produces incorrect results.
Avoid strict aliasing violations by copying from an unsigned long array to
an unsigned int array, then copying back the result. Any sensible compiler
will omit the copies, while avoiding undefined behaviour that would result
from unsafe type punning via pointer type casting.
Thanks to Guido Vranken for reporting the issue and testing the fix.
ok tb@
Diffstat (limited to 'src/lib/libssl/man/SSL_CTX_set_tmp_rsa_callback.3')
0 files changed, 0 insertions, 0 deletions