mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 05:04:02 +02:00
s390/zcrypt: Validate length for CCA ECC private key requests
cca_ecc2protkey() derives the copy length for the CPRB parameter
block directly from the length field in the key token. Reject the
request early if the token length exceeds the available space in the
parameter block.
Fixes: fa6999e326 ("s390/pkey: support CCA and EP11 secure ECC private keys")
Signed-off-by: Holger Dengler <dengler@linux.ibm.com>
Cc: stable@vger.kernel.org # 5.10+
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
This commit is contained in:
parent
06afe425d5
commit
a9ae0f6dd4
|
|
@ -1428,6 +1428,9 @@ int cca_ecc2protkey(u16 cardnr, u16 domain, const u8 *key,
|
|||
} __packed * prepparm;
|
||||
int keylen = ((struct eccprivkeytoken *)key)->len;
|
||||
|
||||
if (keylen > PARMBSIZE - sizeof(struct aureqparm))
|
||||
return -EINVAL;
|
||||
|
||||
/* get already prepared memory for 2 cprbs with param block each */
|
||||
rc = alloc_and_prep_cprbmem(PARMBSIZE, &mem,
|
||||
&preqcblk, &prepcblk, xflags);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user