Blame SOURCES/0046-FIPS-s390x-hardening.patch
|
|
a74baf |
diff --git a/crypto/ec/ecp_s390x_nistp.c b/crypto/ec/ecp_s390x_nistp.c
|
|
|
a74baf |
index 5c70b2d67840..c5726c638bdd 100644
|
|
|
a74baf |
--- a/crypto/ec/ecp_s390x_nistp.c
|
|
|
a74baf |
+++ b/crypto/ec/ecp_s390x_nistp.c
|
|
|
a74baf |
@@ -116,7 +116,7 @@ static int ec_GFp_s390x_nistp_mul(const EC_GROUP *group, EC_POINT *r,
|
|
|
a74baf |
/* Otherwise use default. */
|
|
|
a74baf |
if (rc == -1)
|
|
|
a74baf |
rc = ossl_ec_wNAF_mul(group, r, scalar, num, points, scalars, ctx);
|
|
|
a74baf |
- OPENSSL_cleanse(param + S390X_OFF_SCALAR(len), len);
|
|
|
a74baf |
+ OPENSSL_cleanse(param, sizeof(param));
|
|
|
a74baf |
BN_CTX_end(ctx);
|
|
|
a74baf |
BN_CTX_free(new_ctx);
|
|
|
a74baf |
return rc;
|
|
|
a74baf |
@@ -212,7 +212,7 @@ static ECDSA_SIG *ecdsa_s390x_nistp_sign_sig(const unsigned char *dgst,
|
|
|
a74baf |
|
|
|
a74baf |
ok = 1;
|
|
|
a74baf |
ret:
|
|
|
a74baf |
- OPENSSL_cleanse(param + S390X_OFF_K(len), 2 * len);
|
|
|
a74baf |
+ OPENSSL_cleanse(param, sizeof(param));
|
|
|
a74baf |
if (ok != 1) {
|
|
|
a74baf |
ECDSA_SIG_free(sig);
|
|
|
a74baf |
sig = NULL;
|