crypto: qce - Fix SHA result buffer corruption issues
authorThara Gopinath <thara.gopinath@linaro.org>
Thu, 19 Nov 2020 15:52:31 +0000 (10:52 -0500)
committerHerbert Xu <herbert@gondor.apana.org.au>
Fri, 27 Nov 2020 06:13:40 +0000 (17:13 +1100)
Partial hash was being copied into the final result buffer without the
entire message block processed. Depending on how the end user processes
this result buffer, errors vary from result buffer corruption to result
buffer poisoing. Fix this issue by ensuring that only the final hash value
is copied into the result buffer.

Reviewed-by: Bjorn Andersson <bjorn.andersson@linaro.org>
Signed-off-by: Thara Gopinath <thara.gopinath@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
drivers/crypto/qce/sha.c

index 87be96a..61c418c 100644 (file)
@@ -48,7 +48,7 @@ static void qce_ahash_done(void *data)
        dma_unmap_sg(qce->dev, &rctx->result_sg, 1, DMA_FROM_DEVICE);
 
        memcpy(rctx->digest, result->auth_iv, digestsize);
-       if (req->result)
+       if (req->result && rctx->last_blk)
                memcpy(req->result, result->auth_iv, digestsize);
 
        rctx->byte_count[0] = cpu_to_be32(result->auth_byte_count[0]);