Skip to content

Commit 3b95fdb

Browse files
Eric Biggersgregkh
authored andcommitted
lib/crypto: x86/blake2s: Fix 32-bit arg treated as 64-bit
commit 2f22115 upstream. In the C code, the 'inc' argument to the assembly functions blake2s_compress_ssse3() and blake2s_compress_avx512() is declared with type u32, matching blake2s_compress(). The assembly code then reads it from the 64-bit %rcx. However, the ABI doesn't guarantee zero-extension to 64 bits, nor do gcc or clang guarantee it. Therefore, fix these functions to read this argument from the 32-bit %ecx. In theory, this bug could have caused the wrong 'inc' value to be used, causing incorrect BLAKE2s hashes. In practice, probably not: I've fixed essentially this same bug in many other assembly files too, but there's never been a real report of it having caused a problem. In x86_64, all writes to 32-bit registers are zero-extended to 64 bits. That results in zero-extension in nearly all situations. I've only been able to demonstrate a lack of zero-extension with a somewhat contrived example involving truncation, e.g. when the C code has a u64 variable holding 0x1234567800000040 and passes it as a u32 expecting it to be truncated to 0x40 (64). But that's not what the real code does, of course. Fixes: ed0356e ("crypto: blake2s - x86_64 SIMD implementation") Cc: stable@vger.kernel.org Reviewed-by: Ard Biesheuvel <ardb@kernel.org> Link: https://lore.kernel.org/r/20251102234209.62133-2-ebiggers@kernel.org Signed-off-by: Eric Biggers <ebiggers@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 0eeaa2b commit 3b95fdb

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

lib/crypto/x86/blake2s-core.S

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ SYM_FUNC_START(blake2s_compress_ssse3)
5252
movdqa ROT16(%rip),%xmm12
5353
movdqa ROR328(%rip),%xmm13
5454
movdqu 0x20(%rdi),%xmm14
55-
movq %rcx,%xmm15
55+
movd %ecx,%xmm15
5656
leaq SIGMA+0xa0(%rip),%r8
5757
jmp .Lbeginofloop
5858
.align 32
@@ -176,7 +176,7 @@ SYM_FUNC_START(blake2s_compress_avx512)
176176
vmovdqu (%rdi),%xmm0
177177
vmovdqu 0x10(%rdi),%xmm1
178178
vmovdqu 0x20(%rdi),%xmm4
179-
vmovq %rcx,%xmm5
179+
vmovd %ecx,%xmm5
180180
vmovdqa IV(%rip),%xmm14
181181
vmovdqa IV+16(%rip),%xmm15
182182
jmp .Lblake2s_compress_avx512_mainloop

0 commit comments

Comments
 (0)