forked from OP-TEE/optee_os
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ecc_sign_hash blinding CVE-2018-12437
This originates from the LibTomCrypt upstream mitigation patch: f0a51bbdbd ("ecc_sign_hash blinding CVE-2018-12437") [1] but with modifications to fit into the current LibTomCrypt version used by OP-TEE (use the old function name rand_bn_range(..) instead of the new name rand_bn_upto(..)). Link: [1] libtom/libtomcrypt@f0a51bb Fixes: OP-TEE-2019-0018 Signed-off-by: Joakim Bech <[email protected]> Tested-by: Joakim Bech <[email protected]> (QEMU-v7) Reported-by: Santos Merino del Pozo <[email protected]> Suggested-by: Santos Merino del Pozo <[email protected]> Acked-by: Jerome Forissier <[email protected]>
- Loading branch information
1 parent
0f4b02e
commit 8bbd9b3
Showing
1 changed file
with
11 additions
and
8 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters