mirror of
https://github.com/raspberrypi/linux.git
synced 2025-12-20 00:31:51 +00:00
The sha512 state size in s390_sha_ctx is out by a factor of 8,
fix it so that it stays below HASH_MAX_DESCSIZE. Also fix the
state init function which was writing garbage to the state. Luckily
this is not actually used for anything other than export.
Reported-by: Harald Freudenberger <freude@linux.ibm.com>
Fixes: 572b5c4682 ("crypto: s390/sha512 - Use API partial block handling")
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
43 lines
1.0 KiB
C
43 lines
1.0 KiB
C
/* SPDX-License-Identifier: GPL-2.0+ */
|
|
/*
|
|
* Cryptographic API.
|
|
*
|
|
* s390 generic implementation of the SHA Secure Hash Algorithms.
|
|
*
|
|
* Copyright IBM Corp. 2007
|
|
* Author(s): Jan Glauber (jang@de.ibm.com)
|
|
*/
|
|
#ifndef _CRYPTO_ARCH_S390_SHA_H
|
|
#define _CRYPTO_ARCH_S390_SHA_H
|
|
|
|
#include <crypto/sha2.h>
|
|
#include <crypto/sha3.h>
|
|
#include <linux/types.h>
|
|
|
|
/* must be big enough for the largest SHA variant */
|
|
#define CPACF_MAX_PARMBLOCK_SIZE SHA3_STATE_SIZE
|
|
#define SHA_MAX_BLOCK_SIZE SHA3_224_BLOCK_SIZE
|
|
#define S390_SHA_CTX_SIZE sizeof(struct s390_sha_ctx)
|
|
|
|
struct s390_sha_ctx {
|
|
u64 count; /* message length in bytes */
|
|
union {
|
|
u32 state[CPACF_MAX_PARMBLOCK_SIZE / sizeof(u32)];
|
|
struct {
|
|
u64 state[SHA512_DIGEST_SIZE / sizeof(u64)];
|
|
u64 count_hi;
|
|
} sha512;
|
|
};
|
|
int func; /* KIMD function to use */
|
|
bool first_message_part;
|
|
};
|
|
|
|
struct shash_desc;
|
|
|
|
int s390_sha_update_blocks(struct shash_desc *desc, const u8 *data,
|
|
unsigned int len);
|
|
int s390_sha_finup(struct shash_desc *desc, const u8 *src, unsigned int len,
|
|
u8 *out);
|
|
|
|
#endif
|