From 2e00d0bb059dae7f2a099952fda78cd682f5b3e4 Mon Sep 17 00:00:00 2001 From: tb <> Date: Tue, 9 Jun 2026 05:24:47 +0000 Subject: ecdh: add error codes for point at infinity/not on curve The point at infinity would previously raise EC_R_POINT_AT_INFINITY via EC_POINT_get_affine_coordinates(). For consistency, also raise an error for off-curve points. pointed out by/ok kenjiro --- src/lib/libcrypto/ecdh/ecdh.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) (limited to 'src/lib') diff --git a/src/lib/libcrypto/ecdh/ecdh.c b/src/lib/libcrypto/ecdh/ecdh.c index 51b409a5dd..218c584558 100644 --- a/src/lib/libcrypto/ecdh/ecdh.c +++ b/src/lib/libcrypto/ecdh/ecdh.c @@ -1,4 +1,4 @@ -/* $OpenBSD: ecdh.c,v 1.14 2026/06/08 12:08:08 tb Exp $ */ +/* $OpenBSD: ecdh.c,v 1.15 2026/06/09 05:24:47 tb Exp $ */ /* ==================================================================== * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED. * @@ -169,11 +169,15 @@ ec_key_ecdh_compute_key(unsigned char **out, size_t *out_len, if ((group = EC_KEY_get0_group(ecdh)) == NULL) goto err; - if (EC_POINT_is_at_infinity(group, pub_key)) + if (EC_POINT_is_at_infinity(group, pub_key)) { + ECerror(EC_R_POINT_AT_INFINITY); goto err; + } - if (EC_POINT_is_on_curve(group, pub_key, ctx) <= 0) + if (EC_POINT_is_on_curve(group, pub_key, ctx) <= 0) { + ECerror(EC_R_POINT_IS_NOT_ON_CURVE); goto err; + } if ((point = EC_POINT_new(group)) == NULL) { ECerror(ERR_R_MALLOC_FAILURE); -- cgit v1.2.3-55-g6feb