| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
…ed by an earlier call, relates to github #2487.
|
Thanks for the PR! This is now merged and available on https://www.bouncycastle.org/betas in the latest snapshot. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
AEADBaseEngine.processEncDecBytes (core/src/main/java/org/bouncycastle/crypto/engines/AEADBaseEngine.java:1053) copies its input aside when input == output and the output overlaps it (:1069), but sizes that output as length from processor.getUpdateOutputSize(len) (:1065), the current call's bytes only. The call also writes out the m_bufPos bytes an earlier call left in m_buf (:1082 when encrypting, :1101 and :1118 when decrypting), already counted at :1066 for the output check. When those bytes carry the write into the input, the check reports no overlap and input taken straight from the caller's array (:1089, :1123) or copied into m_buf (:1110, :1115, :1129) is read after output has overwritten it.
Reproduced on released 1.86 and the 1.87-SNAPSHOT beta (1.87.0.20730); main has the same source, compiling to the beta's bytecode. Romulus-N, 4113 bytes in 4096-byte chunks in one array, output offset at the bytes output so far: the second call is processBytes(buf, 4096, 17, buf, 4080) with 16 bytes buffered, the check covers only [4080, 4096) while the write spans [4080, 4112), ciphertext block 256 comes out all zero, and a separate-buffer receiver accepts it, getting the wrong plaintext. Decrypting the valid ciphertext the same way throws InvalidCipherTextException "Romulus-N mac does not match". AsconAEAD128 encrypting 9 then 8 bytes, output one byte ahead, likewise authenticates with the last plaintext byte wrong.
21 of the 23 parameter sets that call CipherTest.testOverlapping are affected at some offset. Grain-128AEAD (own check at :742) and Romulus-M are not. GCMBlockCipher (:395) and ChaCha20Poly1305 (:334) pass getUpdateOutputSize(len), which counts buffered bytes; this change uses the loop's own fields, as ElephantEngine and Grain128AEADEngine override that method.
This change:
Without the change 21 of the 23 fail the new test on the beta; with it all 23 pass. Across RegressionTest.tests only the eight affected LWC tests change status. With no bc-test-data here, their KAT files were not run. :core:checkstyleMain is clean.
Base tree only for the engine: one AEADBaseEngine.java, no META-INF/versions copy, no module-info or OSGi change. A release-note entry is included, happy to move it to another block.