mirror of
https://mirrors.bfsu.edu.cn/git/linux.git
synced 2024-11-11 04:18:39 +08:00
crypto: rsa - fix invalid check for keylen in fips mode
The condition checking allowed key length was invalid. Reported-by: Dan Carpenter <dan.carpenter@oracle.com> Signed-off-by: Tadeusz Struk <tadeusz.struk@intel.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This commit is contained in:
parent
bc3687982b
commit
a9d4f82ff9
@ -28,7 +28,7 @@ int rsa_get_n(void *context, size_t hdrlen, unsigned char tag,
|
||||
return -ENOMEM;
|
||||
|
||||
/* In FIPS mode only allow key size 2K & 3K */
|
||||
if (fips_enabled && (mpi_get_size(key->n) != 256 ||
|
||||
if (fips_enabled && (mpi_get_size(key->n) != 256 &&
|
||||
mpi_get_size(key->n) != 384)) {
|
||||
pr_err("RSA: key size not allowed in FIPS mode\n");
|
||||
mpi_free(key->n);
|
||||
@ -62,7 +62,7 @@ int rsa_get_d(void *context, size_t hdrlen, unsigned char tag,
|
||||
return -ENOMEM;
|
||||
|
||||
/* In FIPS mode only allow key size 2K & 3K */
|
||||
if (fips_enabled && (mpi_get_size(key->d) != 256 ||
|
||||
if (fips_enabled && (mpi_get_size(key->d) != 256 &&
|
||||
mpi_get_size(key->d) != 384)) {
|
||||
pr_err("RSA: key size not allowed in FIPS mode\n");
|
||||
mpi_free(key->d);
|
||||
|
Loading…
Reference in New Issue
Block a user