mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 20:54:03 +02:00
bpftool: Check EVP_Digest when computing excl_prog_hash
bpftool_prog_sign() ignores the return value of EVP_Digest(). If the
digest computation fails (context allocation failure, or a digest
fetch failure under OpenSSL), EVP_Digest() returns 0 and leaves the
output buffer untouched, but the function still reports success.
Fixes: 40863f4d6e ("bpftool: Add support for signing BPF programs")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Quentin Monnet <qmo@kernel.org>
Link: https://lore.kernel.org/bpf/20260708075343.358712-5-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
This commit is contained in:
parent
a2d784869a
commit
576bcaa1f5
|
|
@ -175,8 +175,11 @@ int bpftool_prog_sign(struct bpf_load_and_run_opts *opts)
|
|||
goto cleanup;
|
||||
}
|
||||
|
||||
EVP_Digest(opts->insns, opts->insns_sz, opts->excl_prog_hash,
|
||||
&opts->excl_prog_hash_sz, EVP_sha256(), NULL);
|
||||
if (EVP_Digest(opts->insns, opts->insns_sz, opts->excl_prog_hash,
|
||||
&opts->excl_prog_hash_sz, EVP_sha256(), NULL) != 1) {
|
||||
err = -EIO;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
bd_out = BIO_new(BIO_s_mem());
|
||||
if (!bd_out) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user