aboutsummaryrefslogtreecommitdiff
path: root/sys
diff options
context:
space:
mode:
authorJohn Baldwin <jhb@FreeBSD.org>2021-12-09 19:52:42 +0000
committerJohn Baldwin <jhb@FreeBSD.org>2021-12-09 19:52:42 +0000
commit356c922f74bfcece1f139026897a79c62adbdf50 (patch)
treea4f45837a55a39de6526b3bde8ef8d1e666a9226 /sys
parentc172a407fb0d2e6b4389625ebf604b5a2f831054 (diff)
Diffstat (limited to 'sys')
-rw-r--r--sys/opencrypto/gmac.c6
1 files changed, 4 insertions, 2 deletions
diff --git a/sys/opencrypto/gmac.c b/sys/opencrypto/gmac.c
index 07fa6bffb6e7..690be855288b 100644
--- a/sys/opencrypto/gmac.c
+++ b/sys/opencrypto/gmac.c
@@ -70,7 +70,11 @@ AES_GMAC_Reinit(void *ctx, const uint8_t *iv, u_int ivlen)
agc = ctx;
KASSERT(ivlen <= sizeof agc->counter, ("passed ivlen too large!"));
+ memset(agc->counter, 0, sizeof(agc->counter));
bcopy(iv, agc->counter, ivlen);
+ agc->counter[GMAC_BLOCK_LEN - 1] = 1;
+
+ memset(&agc->hash, 0, sizeof(agc->hash));
}
int
@@ -118,9 +122,7 @@ AES_GMAC_Final(uint8_t *digest, void *ctx)
uint8_t enccntr[GMAC_BLOCK_LEN];
struct gf128 a;
- /* XXX - zero additional bytes? */
agc = ctx;
- agc->counter[GMAC_BLOCK_LEN - 1] = 1;
rijndaelEncrypt(agc->keysched, agc->rounds, agc->counter, enccntr);
a = gf128_add(agc->hash, gf128_read(enccntr));