From: Pauli Date: Sun, 2 Sep 2018 21:37:38 +0000 (+1000) Subject: Check the return from BN_sub() in BN_X931_generate_Xpq(). X-Git-Tag: OpenSSL_1_0_2q~32 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=78ca7b7b319c7027310c56eaa05b8c295624a357;p=oweals%2Fopenssl.git Check the return from BN_sub() in BN_X931_generate_Xpq(). Reviewed-by: Tim Hudson (Merged from https://github.com/openssl/openssl/pull/7088) (cherry picked from commit 6bcfcf16bf6aef4f9ec267d8b86ae1bffd8deab9) --- diff --git a/crypto/bn/bn_x931p.c b/crypto/bn/bn_x931p.c index f444af3fea..116620a138 100644 --- a/crypto/bn/bn_x931p.c +++ b/crypto/bn/bn_x931p.c @@ -223,8 +223,10 @@ int BN_X931_generate_Xpq(BIGNUM *Xp, BIGNUM *Xq, int nbits, BN_CTX *ctx) for (i = 0; i < 1000; i++) { if (!BN_rand(Xq, nbits, 1, 0)) goto err; + /* Check that |Xp - Xq| > 2^(nbits - 100) */ - BN_sub(t, Xp, Xq); + if (!BN_sub(t, Xp, Xq)) + goto err; if (BN_num_bits(t) > (nbits - 100)) break; }