mirror of
https://github.com/openwrt/openwrt.git
synced 2024-12-23 15:32:33 +00:00
1c5cafa3eb
This applies commit 02ac9c94 to fix this OpenSSL Security Advisory issued on 20th April 2023[1]: Input buffer over-read in AES-XTS implementation on 64 bit ARM (CVE-2023-1255) ============================================================== Severity: Low Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it to read past the input buffer, leading to a crash. Impact summary: Applications that use the AES-XTS algorithm on the 64 bit ARM platform can crash in rare circumstances. The AES-XTS algorithm is usually used for disk encryption. The AES-XTS cipher decryption implementation for 64 bit ARM platform will read past the end of the ciphertext buffer if the ciphertext size is 4 mod 5 in 16 byte blocks, e.g. 144 bytes or 1024 bytes. If the memory after the ciphertext buffer is unmapped, this will trigger a crash which results in a denial of service. If an attacker can control the size and location of the ciphertext buffer being decrypted by an application using AES-XTS on 64 bit ARM, the application is affected. This is fairly unlikely making this issue a Low severity one. 1. https://www.openssl.org/news/secadv/20230420.txt Signed-off-by: Eneas U de Queiroz <cotequeiroz@gmail.com> |
||
---|---|---|
.. | ||
100-Configure-afalg-support.patch | ||
110-openwrt_targets.patch | ||
120-strip-cflags-from-binary.patch | ||
130-dont-build-fuzz-docs.patch | ||
140-allow-prefer-chacha20.patch | ||
150-openssl.cnf-add-engines-conf.patch | ||
200-x509-excessive-resource-use-verifying-policy-constra.patch | ||
210-Ensure-that-EXFLAG_INVALID_POLICY-is-checked-even-in.patch | ||
220-aesv8-armx.pl-Avoid-buffer-overrread-in-AES-XTS-decr.patch | ||
500-e_devcrypto-default-to-not-use-digests-in-engine.patch | ||
510-e_devcrypto-ignore-error-when-closing-session.patch |