On Thu, Dec 12, 2013 at 5:31 PM, Niels Möller <[email protected]> wrote:
>>> That said, Nettle shouldn't do unbounded stack allocations in this case, >>> it ought to use malloc, or abort or fail in some other *reliable* >>> fashion. (I think having some documented limit on keysize would be >>> acceptable, but I'm leaning towards saying that it's better to just use >>> heap allcoation). >>> Do you agree? >> Yes, that would be much better. Do you want me to send an updated patch? > That would be good. I think it makes sense to use gmp's allocation > functions here, so the user can override allocation, without having to > do it separately for nettle and gmp. See gmp-glue.c:gmp_alloc_limbs. What about the attached patch?
From c1ddf689f217e87504080331290ba8dc5ab24365 Mon Sep 17 00:00:00 2001 From: Nikos Mavrogiannopoulos <[email protected]> Date: Fri, 13 Dec 2013 10:58:30 +0100 Subject: [PATCH] Introduced TMP_GMP_ALLOC macro for temporary allocations of potentially large data. This prevents big data allocations on stack by using TMP_GMP_ALLOC in places where TMP_ALLOC was called with potentially large data size. --- Makefile.in | 2 +- bignum-internal.h | 57 +++++++++++++++++++++++++++++++++++++++++++++++++++++ bignum-next-prime.c | 8 +++++--- bignum-random.c | 9 ++++++--- pkcs1-decrypt.c | 31 ++++++++++++++++++++++------- pkcs1-encrypt.c | 7 +++++-- pkcs1-rsa-digest.c | 12 ++++++++--- pkcs1-rsa-md5.c | 23 +++++++++++++++------ pkcs1-rsa-sha1.c | 23 +++++++++++++++------ pkcs1-rsa-sha256.c | 23 +++++++++++++++------ pkcs1-rsa-sha512.c | 23 +++++++++++++++------ 11 files changed, 175 insertions(+), 43 deletions(-) create mode 100644 bignum-internal.h diff --git a/Makefile.in b/Makefile.in index 05e6ade..39274df 100644 --- a/Makefile.in +++ b/Makefile.in @@ -182,7 +182,7 @@ DISTFILES = $(SOURCES) $(HEADERS) getopt.h .bootstrap run-tests \ cast128_sboxes.h desinfo.h desCode.h \ nettle-internal.h nettle-write.h prime-list.h \ gmp-glue.h ecc-internal.h \ - mini-gmp.h mini-gmp.c asm.m4 \ + mini-gmp.h mini-gmp.c asm.m4 bignum-internal.h \ nettle.texinfo nettle.info nettle.html nettle.pdf sha-example.c # Rules building static libraries diff --git a/bignum-internal.h b/bignum-internal.h new file mode 100644 index 0000000..c73ea47 --- /dev/null +++ b/bignum-internal.h @@ -0,0 +1,57 @@ +/* bignum-internal.h + * + */ + +/* nettle, low-level cryptographics library + * + * Copyright (C) 2013 Red Hat + * + * The nettle library is free software; you can redistribute it and/or modify + * it under the terms of the GNU Lesser General Public License as published by + * the Free Software Foundation; either version 2.1 of the License, or (at your + * option) any later version. + * + * The nettle library is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public + * License for more details. + * + * You should have received a copy of the GNU Lesser General Public License + * along with the nettle library; see the file COPYING.LIB. If not, write to + * the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, + * MA 02111-1301, USA. + */ + +#ifndef BIGNUM_INTERNAL_H +# define BIGNUM_INTERNAL_H + +#include <assert.h> + +inline static void* _tmp_gmp_alloc(unsigned* out_n, size_t n) +{ + void *(*alloc_func)(size_t); + assert (n > 0); + + mp_get_memory_functions(&alloc_func, NULL, NULL); + + *out_n = n; + return alloc_func (n); +} + +inline static void _tmp_gmp_free(void* p, size_t n) +{ + void (*free_func)(void *, size_t); + assert (n > 0); + assert (p != 0); + mp_get_memory_functions (NULL, NULL, &free_func); + + free_func (p, (size_t) n); +} + +#define TMP_GMP_DECL(name, type) type *name; \ + unsigned name##_gmp_size +#define TMP_GMP_ALLOC(name, size) \ + (name = _tmp_gmp_alloc(&name##_gmp_size, sizeof (*name) * (size))) +#define TMP_GMP_FREE(name) (_tmp_gmp_free(name, name##_gmp_size)) + +#endif diff --git a/bignum-next-prime.c b/bignum-next-prime.c index 58a4df8..bc89399 100644 --- a/bignum-next-prime.c +++ b/bignum-next-prime.c @@ -31,6 +31,7 @@ #include <stdlib.h> #include "bignum.h" +#include "bignum-internal.h" #include "nettle-internal.h" @@ -77,9 +78,8 @@ nettle_next_prime(mpz_t p, mpz_t n, unsigned count, unsigned prime_limit, void *progress_ctx, nettle_progress_func *progress) { mpz_t tmp; - TMP_DECL(moduli, unsigned, NUMBER_OF_PRIMES); - unsigned difference; + TMP_GMP_DECL(moduli, unsigned); if (prime_limit > NUMBER_OF_PRIMES) prime_limit = NUMBER_OF_PRIMES; @@ -112,7 +112,8 @@ nettle_next_prime(mpz_t p, mpz_t n, unsigned count, unsigned prime_limit, between the 5760 odd numbers in this interval that have no factor in common with 15015. */ - TMP_ALLOC(moduli, prime_limit); + TMP_GMP_ALLOC(moduli, prime_limit); + { unsigned i; for (i = 0; i < prime_limit; i++) @@ -159,4 +160,5 @@ nettle_next_prime(mpz_t p, mpz_t n, unsigned count, unsigned prime_limit, #endif } mpz_clear(tmp); + TMP_GMP_FREE(moduli); } diff --git a/bignum-random.c b/bignum-random.c index f305f04..07ae1ba 100644 --- a/bignum-random.c +++ b/bignum-random.c @@ -30,6 +30,7 @@ #include <stdlib.h> #include "bignum.h" +#include "bignum-internal.h" #include "nettle-internal.h" void @@ -38,15 +39,17 @@ nettle_mpz_random_size(mpz_t x, unsigned bits) { unsigned length = (bits + 7) / 8; - TMP_DECL(data, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(data, length); + TMP_GMP_DECL(data, uint8_t); - random(ctx, length, data); + TMP_GMP_ALLOC(data, length); + random(ctx, length, data); nettle_mpz_set_str_256_u(x, length, data); if (bits % 8) mpz_fdiv_r_2exp(x, x, bits); + + TMP_GMP_FREE(data); } /* Returns a random number x, 0 <= x < n */ diff --git a/pkcs1-decrypt.c b/pkcs1-decrypt.c index 02d3728..96016e0 100644 --- a/pkcs1-decrypt.c +++ b/pkcs1-decrypt.c @@ -31,6 +31,7 @@ #include "pkcs1.h" #include "bignum.h" +#include "bignum-internal.h" #include "nettle-internal.h" int @@ -38,35 +39,51 @@ pkcs1_decrypt (size_t key_size, const mpz_t m, size_t *length, uint8_t *message) { - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); + TMP_GMP_DECL(em, uint8_t); uint8_t *terminator; size_t padding; size_t message_length; + int ret; - TMP_ALLOC(em, key_size); + TMP_GMP_ALLOC(em, key_size); nettle_mpz_get_str_256(key_size, em, m); /* Check format */ if (em[0] || em[1] != 2) - return 0; + { + ret = 0; + goto err; + } terminator = memchr(em + 2, 0, key_size - 2); if (!terminator) - return 0; + { + ret = 0; + goto err; + } padding = terminator - (em + 2); if (padding < 8) - return 0; + { + ret = 0; + goto err; + } message_length = key_size - 3 - padding; if (*length < message_length) - return 0; + { + ret = 0; + goto err; + } memcpy(message, terminator + 1, message_length); *length = message_length; - return 1; + ret = 1; +err: + TMP_GMP_FREE(em); + return ret; } diff --git a/pkcs1-encrypt.c b/pkcs1-encrypt.c index 69ef5bc..9f34343 100644 --- a/pkcs1-encrypt.c +++ b/pkcs1-encrypt.c @@ -34,6 +34,7 @@ #include "pkcs1.h" #include "bignum.h" +#include "bignum-internal.h" #include "nettle-internal.h" int @@ -43,7 +44,7 @@ pkcs1_encrypt (size_t key_size, size_t length, const uint8_t *message, mpz_t m) { - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); + TMP_GMP_DECL(em, uint8_t); size_t padding; size_t i; @@ -63,7 +64,7 @@ pkcs1_encrypt (size_t key_size, padding = key_size - length - 3; assert(padding >= 8); - TMP_ALLOC(em, key_size - 1); + TMP_GMP_ALLOC(em, key_size - 1); em[0] = 2; random(random_ctx, padding, em + 1); @@ -77,5 +78,7 @@ pkcs1_encrypt (size_t key_size, memcpy(em + padding + 2, message, length); nettle_mpz_set_str_256_u(m, key_size - 1, em); + + TMP_GMP_FREE(em); return 1; } diff --git a/pkcs1-rsa-digest.c b/pkcs1-rsa-digest.c index debfb28..5f348ae 100644 --- a/pkcs1-rsa-digest.c +++ b/pkcs1-rsa-digest.c @@ -29,21 +29,27 @@ #include "pkcs1.h" #include "bignum.h" +#include "bignum-internal.h" #include "nettle-internal.h" int pkcs1_rsa_digest_encode(mpz_t m, size_t key_size, size_t di_length, const uint8_t *digest_info) { - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); if (_pkcs1_signature_prefix(key_size, em, di_length, digest_info, 0)) { nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } diff --git a/pkcs1-rsa-md5.c b/pkcs1-rsa-md5.c index b118b4f..87b423a 100644 --- a/pkcs1-rsa-md5.c +++ b/pkcs1-rsa-md5.c @@ -34,6 +34,7 @@ #include "rsa.h" #include "bignum.h" +#include "bignum-internal.h" #include "pkcs1.h" #include "nettle-internal.h" @@ -65,8 +66,9 @@ int pkcs1_rsa_md5_encode(mpz_t m, size_t key_size, struct md5_ctx *hash) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(md5_prefix), @@ -76,18 +78,23 @@ pkcs1_rsa_md5_encode(mpz_t m, size_t key_size, struct md5_ctx *hash) { md5_digest(hash, MD5_DIGEST_SIZE, p); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } int pkcs1_rsa_md5_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(md5_prefix), @@ -97,8 +104,12 @@ pkcs1_rsa_md5_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { memcpy(p, digest, MD5_DIGEST_SIZE); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } diff --git a/pkcs1-rsa-sha1.c b/pkcs1-rsa-sha1.c index 781d75d..84ebb4c 100644 --- a/pkcs1-rsa-sha1.c +++ b/pkcs1-rsa-sha1.c @@ -34,6 +34,7 @@ #include "rsa.h" #include "bignum.h" +#include "bignum-internal.h" #include "pkcs1.h" #include "nettle-internal.h" @@ -65,8 +66,9 @@ int pkcs1_rsa_sha1_encode(mpz_t m, size_t key_size, struct sha1_ctx *hash) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(sha1_prefix), @@ -76,18 +78,23 @@ pkcs1_rsa_sha1_encode(mpz_t m, size_t key_size, struct sha1_ctx *hash) { sha1_digest(hash, SHA1_DIGEST_SIZE, p); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } int pkcs1_rsa_sha1_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(sha1_prefix), @@ -97,8 +104,12 @@ pkcs1_rsa_sha1_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { memcpy(p, digest, SHA1_DIGEST_SIZE); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } diff --git a/pkcs1-rsa-sha256.c b/pkcs1-rsa-sha256.c index a4d5bb1..2fde45f 100644 --- a/pkcs1-rsa-sha256.c +++ b/pkcs1-rsa-sha256.c @@ -34,6 +34,7 @@ #include "rsa.h" #include "bignum.h" +#include "bignum-internal.h" #include "pkcs1.h" #include "nettle-internal.h" @@ -63,8 +64,9 @@ int pkcs1_rsa_sha256_encode(mpz_t m, size_t key_size, struct sha256_ctx *hash) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(sha256_prefix), @@ -74,18 +76,23 @@ pkcs1_rsa_sha256_encode(mpz_t m, size_t key_size, struct sha256_ctx *hash) { sha256_digest(hash, SHA256_DIGEST_SIZE, p); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } int pkcs1_rsa_sha256_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(sha256_prefix), @@ -95,8 +102,12 @@ pkcs1_rsa_sha256_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { memcpy(p, digest, SHA256_DIGEST_SIZE); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } diff --git a/pkcs1-rsa-sha512.c b/pkcs1-rsa-sha512.c index 03acb69..078851d 100644 --- a/pkcs1-rsa-sha512.c +++ b/pkcs1-rsa-sha512.c @@ -34,6 +34,7 @@ #include "rsa.h" #include "bignum.h" +#include "bignum-internal.h" #include "pkcs1.h" #include "nettle-internal.h" @@ -63,8 +64,9 @@ int pkcs1_rsa_sha512_encode(mpz_t m, size_t key_size, struct sha512_ctx *hash) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(sha512_prefix), @@ -74,18 +76,23 @@ pkcs1_rsa_sha512_encode(mpz_t m, size_t key_size, struct sha512_ctx *hash) { sha512_digest(hash, SHA512_DIGEST_SIZE, p); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } int pkcs1_rsa_sha512_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { uint8_t *p; - TMP_DECL(em, uint8_t, NETTLE_MAX_BIGNUM_SIZE); - TMP_ALLOC(em, key_size); + TMP_GMP_DECL(em, uint8_t); + + TMP_GMP_ALLOC(em, key_size); p = _pkcs1_signature_prefix(key_size, em, sizeof(sha512_prefix), @@ -95,8 +102,12 @@ pkcs1_rsa_sha512_encode_digest(mpz_t m, size_t key_size, const uint8_t *digest) { memcpy(p, digest, SHA512_DIGEST_SIZE); nettle_mpz_set_str_256_u(m, key_size, em); + TMP_GMP_FREE(em); return 1; } else - return 0; + { + TMP_GMP_FREE(em); + return 0; + } } -- 1.8.4.2
_______________________________________________ nettle-bugs mailing list [email protected] http://lists.lysator.liu.se/mailman/listinfo/nettle-bugs
