diff options
| author | tb <> | 2022-03-29 14:03:12 +0000 |
|---|---|---|
| committer | tb <> | 2022-03-29 14:03:12 +0000 |
| commit | 89475160d42bc14609305f5d10c30b9f6042c4b0 (patch) | |
| tree | f3eb1afef5a9f1e2847d1adc42bdfa0cefcf4a53 /src | |
| parent | 5c5a9e687c0eb72164516557865831f499cc3e04 (diff) | |
| download | openbsd-89475160d42bc14609305f5d10c30b9f6042c4b0.tar.gz openbsd-89475160d42bc14609305f5d10c30b9f6042c4b0.tar.bz2 openbsd-89475160d42bc14609305f5d10c30b9f6042c4b0.zip | |
Bound cofactor in EC_GROUP_set_generator()
Instead of bounding only bounding the group order, also bound the
cofactor using Hasse's theorem. This could probably be made a lot
tighter since all curves of cryptographic interest have small
cofactors, but for now this is good enough.
A timeout found by oss-fuzz creates a "group" with insane parameters
over a 40-bit field: the order is 14464, and the cofactor has 4196223
bits (which is obviously impossible by Hasse's theorem). These led to
running an expensive loop in ec_GFp_simple_mul_ct() millions of times.
Fixes oss-fuzz #46056
Diagnosed and fix joint with jsing
ok inoguchi jsing (previous version)
Diffstat (limited to 'src')
| -rw-r--r-- | src/lib/libcrypto/ec/ec_lib.c | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/src/lib/libcrypto/ec/ec_lib.c b/src/lib/libcrypto/ec/ec_lib.c index 455d44a942..888f1edfcf 100644 --- a/src/lib/libcrypto/ec/ec_lib.c +++ b/src/lib/libcrypto/ec/ec_lib.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: ec_lib.c,v 1.43 2022/03/29 13:48:40 tb Exp $ */ | 1 | /* $OpenBSD: ec_lib.c,v 1.44 2022/03/29 14:03:12 tb Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Originally written by Bodo Moeller for the OpenSSL project. | 3 | * Originally written by Bodo Moeller for the OpenSSL project. |
| 4 | */ | 4 | */ |
| @@ -385,6 +385,12 @@ EC_GROUP_set_generator(EC_GROUP *group, const EC_POINT *generator, | |||
| 385 | } else if (!ec_guess_cofactor(group)) | 385 | } else if (!ec_guess_cofactor(group)) |
| 386 | return 0; | 386 | return 0; |
| 387 | 387 | ||
| 388 | /* Use Hasse's theorem to bound the cofactor. */ | ||
| 389 | if (BN_num_bits(&group->cofactor) > BN_num_bits(&group->field) + 1) { | ||
| 390 | ECerror(EC_R_INVALID_GROUP_ORDER); | ||
| 391 | return 0; | ||
| 392 | } | ||
| 393 | |||
| 388 | return 1; | 394 | return 1; |
| 389 | } | 395 | } |
| 390 | 396 | ||
