From: Pauli Date: Sun, 28 Oct 2018 22:24:22 +0000 (+1000) Subject: Merge DSA reallocation timing fix CVE-2018-0734. X-Git-Tag: OpenSSL_1_0_2q~11 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=43e6a58d4991a451daf4891ff05a48735df871ac;p=oweals%2Fopenssl.git Merge DSA reallocation timing fix CVE-2018-0734. Reviewed-by: Richard Levitte (Merged from https://github.com/openssl/openssl/pull/7513) --- diff --git a/crypto/dsa/dsa_ossl.c b/crypto/dsa/dsa_ossl.c index 2dcfedeeee..100e269268 100644 --- a/crypto/dsa/dsa_ossl.c +++ b/crypto/dsa/dsa_ossl.c @@ -279,7 +279,7 @@ static int dsa_sign_setup(DSA *dsa, BN_CTX *ctx_in, BIGNUM **kinvp, goto err; /* Preallocate space */ - q_bits = BN_num_bits(dsa->q); + q_bits = BN_num_bits(dsa->q) + sizeof(dsa->q->d[0]) * 16; if (!BN_set_bit(&k, q_bits) || !BN_set_bit(&l, q_bits) || !BN_set_bit(&m, q_bits))