From 3513b0c3d9711e5eee47ef15b7913f0ce4483663 Mon Sep 17 00:00:00 2001 From: Ben Noordhuis Date: Thu, 29 Nov 2018 11:09:12 +0100 Subject: [PATCH] crypto: harden bignum-to-binary conversions PR-URL: https://github.com/nodejs/node/pull/24719 Refs: https://github.com/nodejs/node/issues/24645 Reviewed-By: Colin Ihrig Reviewed-By: James M Snell --- src/node_crypto.cc | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/src/node_crypto.cc b/src/node_crypto.cc index 16d1951ff72eaa..f2223a324bcf70 100644 --- a/src/node_crypto.cc +++ b/src/node_crypto.cc @@ -4211,9 +4211,11 @@ void DiffieHellman::GenerateKeys(const FunctionCallbackInfo& args) { const BIGNUM* pub_key; DH_get0_key(diffieHellman->dh_.get(), &pub_key, nullptr); - size_t size = BN_num_bytes(pub_key); + const int size = BN_num_bytes(pub_key); + CHECK_GE(size, 0); char* data = Malloc(size); - BN_bn2bin(pub_key, reinterpret_cast(data)); + CHECK_EQ(size, + BN_bn2binpad(pub_key, reinterpret_cast(data), size)); args.GetReturnValue().Set(Buffer::New(env, data, size).ToLocalChecked()); } @@ -4229,9 +4231,11 @@ void DiffieHellman::GetField(const FunctionCallbackInfo& args, const BIGNUM* num = get_field(dh->dh_.get()); if (num == nullptr) return env->ThrowError(err_if_null); - size_t size = BN_num_bytes(num); + const int size = BN_num_bytes(num); + CHECK_GE(size, 0); char* data = Malloc(size); - BN_bn2bin(num, reinterpret_cast(data)); + CHECK_EQ(size, + BN_bn2binpad(num, reinterpret_cast(data), size)); args.GetReturnValue().Set(Buffer::New(env, data, size).ToLocalChecked()); } @@ -4567,13 +4571,9 @@ void ECDH::GetPrivateKey(const FunctionCallbackInfo& args) { if (b == nullptr) return env->ThrowError("Failed to get ECDH private key"); - int size = BN_num_bytes(b); + const int size = BN_num_bytes(b); unsigned char* out = node::Malloc(size); - - if (size != BN_bn2bin(b, out)) { - free(out); - return env->ThrowError("Failed to convert ECDH private key to Buffer"); - } + CHECK_EQ(size, BN_bn2binpad(b, out, size)); Local buf = Buffer::New(env, reinterpret_cast(out), size).ToLocalChecked();