From: Patrick Steuer Date: Sat, 22 Feb 2020 00:20:09 +0000 (+0100) Subject: AES CTR-DRGB: do not leak timing information X-Git-Tag: OpenSSL_1_1_1g~15 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=9cc834d966ea5afc38fb829bfe498aed4c5d498d;p=oweals%2Fopenssl.git AES CTR-DRGB: do not leak timing information Signed-off-by: Patrick Steuer Reviewed-by: Tomas Mraz Reviewed-by: Paul Dale (Merged from https://github.com/openssl/openssl/pull/11147) (cherry picked from commit 069165d10646a22000c596095cc04d43bbf1f807) --- diff --git a/crypto/rand/drbg_ctr.c b/crypto/rand/drbg_ctr.c index 93b82f34ce..f41484e9d5 100644 --- a/crypto/rand/drbg_ctr.c +++ b/crypto/rand/drbg_ctr.c @@ -21,19 +21,15 @@ static void inc_128(RAND_DRBG_CTR *ctr) { - int i; - unsigned char c; - unsigned char *p = &ctr->V[15]; - - for (i = 0; i < 16; i++, p--) { - c = *p; - c++; - *p = c; - if (c != 0) { - /* If we didn't wrap around, we're done. */ - break; - } - } + unsigned char *p = &ctr->V[0]; + u32 n = 16, c = 1; + + do { + --n; + c += p[n]; + p[n] = (u8)c; + c >>= 8; + } while (n); } static void ctr_XOR(RAND_DRBG_CTR *ctr, const unsigned char *in, size_t inlen)