Skip to content

Commit ad382c5

Browse files
Eric Biggersgregkh
authored andcommitted
crypto: drbg - Fix the fips_enabled priority boost
commit a8a1f93 upstream. When fips_enabled=1, it seems to have been intended for one of the algorithms defined in crypto/drbg.c to be the highest priority "stdrng" algorithm, so that it is what is used by "stdrng" users. However, the code only boosts the priority to 400, which is less than the priority 500 used in drivers/crypto/caam/caamprng.c. Thus, the CAAM RNG could be used instead. Fix this by boosting the priority by 2000 instead of 200. Fixes: 541af94 ("crypto: drbg - SP800-90A Deterministic Random Bit Generator") Cc: stable@vger.kernel.org Signed-off-by: Eric Biggers <ebiggers@kernel.org> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 7af989e commit ad382c5

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

crypto/drbg.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2095,7 +2095,7 @@ static inline void __init drbg_fill_array(struct rng_alg *alg,
20952095
* it is selected.
20962096
*/
20972097
if (fips_enabled)
2098-
alg->base.cra_priority += 200;
2098+
alg->base.cra_priority += 2000;
20992099

21002100
alg->base.cra_ctxsize = sizeof(struct drbg_state);
21012101
alg->base.cra_module = THIS_MODULE;

0 commit comments

Comments
 (0)