Repository navigation
AES Key Wrap Segfault #15009
Copy link
Copy link
Closed
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.opensslIssues and PRs related to the OpenSSL dependency.Issues and PRs related to the OpenSSL dependency.
Description
Activity
- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.opensslIssues and PRs related to the OpenSSL dependency.Issues and PRs related to the OpenSSL dependency.
on Aug 24, 2017 I can reproduce this with v8.4.0.
Process 14998 stopped * thread #1, name = 'node', stop reason = signal SIGSEGV: invalid address (fault address: 0x24dc000) frame #0: 0x0000000000a7cbe0 node`_x86_64_AES_encrypt_compact + 48 node`_x86_64_AES_encrypt_compact: -> 0xa7cbe0 <+48>: xorl (%r15), %eax 0xa7cbe3 <+51>: xorl 0x4(%r15), %ebx 0xa7cbe7 <+55>: xorl 0x8(%r15), %ecx 0xa7cbeb <+59>: xorl 0xc(%r15), %edx (lldb) register read r15 r15 = 0x00000000024dc000 (lldb) memory read 0x00000000024dc000 error: memory read failed for 0x24dc000Reacted by EternalDeiwos- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Aug 24, 2017 @nodejs/crypto
The following patch would fix this. I'll submit a PR with tests tomorrow.
diff --git a/src/node_crypto.cc b/src/node_crypto.cc index 1fa522d..e8391dc 100644 --- a/src/node_crypto.cc +++ b/src/node_crypto.cc @@ -3396,13 +3396,18 @@ void CipherBase::InitIv(const char* cipher_type, } const int expected_iv_len = EVP_CIPHER_iv_length(cipher); - const bool is_gcm_mode = (EVP_CIPH_GCM_MODE == EVP_CIPHER_mode(cipher)); + const int mode = EVP_CIPHER_mode(cipher); + const bool is_gcm_mode = (EVP_CIPH_GCM_MODE == mode); if (is_gcm_mode == false && iv_len != expected_iv_len) { return env()->ThrowError("Invalid IV length"); } EVP_CIPHER_CTX_init(&ctx_); + + if (mode == EVP_CIPH_WRAP_MODE) + EVP_CIPHER_CTX_set_flags(&ctx_, EVP_CIPHER_CTX_FLAG_WRAP_ALLOW); + const bool encrypt = (kind_ == kCipher); EVP_CipherInit_ex(&ctx_, cipher, nullptr, nullptr, nullptr, encrypt);
$ ./node ~/test_aes_wrap.js RESULT <Buffer 1f a6 8b 0a 81 12 b4 47 ae f3 4b d8 fb 5a 7b 82 9d 3e 86 23 71 d2 cf e5> <Buffer >
@shigeki thanks for the fix 👍
- ghost added a commit that references this issue
on Aug 30, 2017 - ghost added a commit that references this issue
on Aug 30, 2017 - added a commit that references this issue
on Aug 31, 2017 - added a commit that references this issue
on Oct 29, 2017 - added a commit that references this issue
on Nov 14, 2017 - added 2 commits that reference this issue
on Nov 21, 2017 - added a commit that references this issue
on Jul 27, 2026
Metadata
Metadata
Assignees
Labels
confirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.opensslIssues and PRs related to the OpenSSL dependency.Issues and PRs related to the OpenSSL dependency.
CC @thelunararmy
We're trying to do aes key wrapping for our nodejs webcrypto implementation. We were having some trouble so we made the following test script (using data from RFC3394):
Running this script causes node to segfault. Any ideas?