Skip to content

Fix regressions introduced in #1388#1421

Merged
newpavlov merged 3 commits intoRustCrypto:masterfrom
lmaotrigine:patch-1
Jan 4, 2024
Merged

Fix regressions introduced in #1388#1421
newpavlov merged 3 commits intoRustCrypto:masterfrom
lmaotrigine:patch-1

Conversation

@lmaotrigine
Copy link
Contributor

@lmaotrigine lmaotrigine commented Dec 16, 2023

When StreamCipherCoreWrapper is instantiated via KeyIvInit::new or KeyInit::new, the first byte of the buffer remains zero. This makes the initial call to StreamCipherCoreWrapper::get_pos result in undefined behaviour in release builds.

Additionally, the wrong length is used to index into the buffer when XORing with the tail end of the stream after blocks are processed.

I am performing this commit on a mobile device using the web interface, so I might have missed things. These two issues immediately jumped at me while casually browsing the code.

I see no open issue regarding this and no other PRs attempting to fix this, so I'm just doing this hasty fix. If there is a more fundamental issue at play here that I am not seeing, feel free to suggest/open a fix that supersedes this.

Also, if I'm way off base here, I apologise and you may close this PR, because I'm making this change solely after a glance through the source without performing any testing.

Since this change hasn't rolled out publicly and isn't in use by any crates in RustCrypto/stream-ciphers, I am thinking this doesn't constitute a security vulnerability and directly submitting a patch is OK.

Cheers.

When `StreamCipherCoreWrapper` is instantiated via `KeyIvInit::new` or `KeyInit::new`, the lowest bit of the buffer remains zero. This makes the initial call to `StreamCipherCoreWrapper::get_pos` result in undefined behaviour in release builds.

Additionally, the wrong length is used to index into the buffer when XORing with the tail end of the stream after blocks are processed.

I am performing this commit on a mobile device using the web interface, so I might have missed things. These two issues immediately jumped at me while casually browsing the code.

I see no open issue regarding this and no other PRs attempting to fix this, so I'm just doing this hasty fix. If there is a more fundamental issue at play here that I am not seeing, feel free to suggest/open a fix that supersedes this.

Also, if I'm way off base here, I apologise and you may close this PR, because I'm making this change solely after a glance through the source without performing any testing.
Please squash these when merging thanks.
@tarcieri tarcieri requested a review from newpavlov December 29, 2023 17:51
@newpavlov
Copy link
Member

Thank you! In future we probably should add proper testing of the wrappers to the cipher crate instead of relying on cipher implementations.

@newpavlov newpavlov merged commit 77445d1 into RustCrypto:master Jan 4, 2024
@lmaotrigine lmaotrigine deleted the patch-1 branch January 5, 2024 02:20
@tarcieri tarcieri mentioned this pull request Feb 4, 2026
tarcieri added a commit that referenced this pull request Feb 4, 2026
### Added
- Traits for tweakable block ciphers (#1721)
- Methods for writing keystream (#1907)

### Changed
- Replaced `generic-array` with `hybrid-array` (#1358)
- Rename `BlockCipher*`/`BlockMode*` (#1482)
  - `BlockEncrypt` => `BlockCipherEncrypt`
  - `BlockDecrypt` => `BlockCipherDecrypt`
  - `BlockEncryptMut` => `BlockModeEncrypt`
  - `BlockDecryptMut` => `BlockModeDecrypt`
- Split `BlockBackend` traits into 4 specific traits: (#1636)
  - `BlockCipherEncBackend`
  - `BlockCipherDecBackend`
  - `BlockModeEncBackend`
  - `BlockModeDecBackend`
- Edition changed to 2024 and MSRV bumped to 1.85 (#1759)
- Use `block_buffer::ReadBuffer` in `StreamCipherCoreWrapper` (#1959)
- Re-export of `crypto-common` moved to `cipher::common` (#2237, #2260)
- `crypto-common` dependency bumped to v0.2 (#2276)
- `blobby` requirement bumped to v0.4 (#2147)
- `inout` dependency bumped to v0.2.2 (#2149)

### Fixed
- Bugs in `StreamCipherCoreWrapper` trait implementations (#1421)
- Seeking implementation in the stream cipher wrapper (#2052)

### Removed
- `std` feature (#1691)
- `BlockCipherEncrypt::encrypt_padded*` and
`BlockCipherDecrypt::decrypt_padded*` methods.
Users of the ECB mode should use the `ecb-mode` crate instead. (#2245)
- `AsyncStreamCipher` trait (#2280)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants