summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorYehuda Sadeh <yehuda@hq.newdream.net>2009-03-27 13:03:51 +0800
committerHerbert Xu <herbert@gondor.apana.org.au>2009-03-27 13:03:51 +0800
commitf4f689933c63e0fbfba62f2a80efb2b424b139ae (patch)
tree6dfaca5c03cd0036df3ab393824fe311ce78855a
parent3341323bb4c198f704cffbfdda37bcec1226ef7d (diff)
downloadlinux-3.10-f4f689933c63e0fbfba62f2a80efb2b424b139ae.tar.gz
linux-3.10-f4f689933c63e0fbfba62f2a80efb2b424b139ae.tar.bz2
linux-3.10-f4f689933c63e0fbfba62f2a80efb2b424b139ae.zip
crypto: shash - Fix unaligned calculation with short length
When the total length is shorter than the calculated number of unaligned bytes, the call to shash->update breaks. For example, calling crc32c on unaligned buffer with length of 1 can result in a system crash. Signed-off-by: Yehuda Sadeh <yehuda@hq.newdream.net> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
-rw-r--r--crypto/shash.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/crypto/shash.c b/crypto/shash.c
index 7a659733f94..2ccc8b0076c 100644
--- a/crypto/shash.c
+++ b/crypto/shash.c
@@ -77,6 +77,9 @@ static int shash_update_unaligned(struct shash_desc *desc, const u8 *data,
u8 buf[shash_align_buffer_size(unaligned_len, alignmask)]
__attribute__ ((aligned));
+ if (unaligned_len > len)
+ unaligned_len = len;
+
memcpy(buf, data, unaligned_len);
return shash->update(desc, buf, unaligned_len) ?: