|
| 1 | +From 7a6ba45e89d339b37c4f47538768451fa58410aa Mon Sep 17 00:00:00 2001 |
| 2 | +From: Kanishk-Bansal < [email protected]> |
| 3 | +Date: Wed, 26 Mar 2025 17:04:23 +0000 |
| 4 | +Subject: [PATCH] CVE-2022-45142 |
| 5 | + |
| 6 | +Upstream Reference [Mailing List]: https://www.openwall.com/lists/oss-security/2023/02/08/1 |
| 7 | + |
| 8 | +--- |
| 9 | + lib/gssapi/krb5/arcfour.c | 4 ++-- |
| 10 | + 1 file changed, 2 insertions(+), 2 deletions(-) |
| 11 | + |
| 12 | +diff --git a/lib/gssapi/krb5/arcfour.c b/lib/gssapi/krb5/arcfour.c |
| 13 | +index aa03cbe..c6c15eb 100644 |
| 14 | +--- a/lib/gssapi/krb5/arcfour.c |
| 15 | ++++ b/lib/gssapi/krb5/arcfour.c |
| 16 | +@@ -365,7 +365,7 @@ _gssapi_verify_mic_arcfour(OM_uint32 * minor_status, |
| 17 | + return GSS_S_FAILURE; |
| 18 | + } |
| 19 | + |
| 20 | +- cmp = (ct_memcmp(cksum_data, p + 8, 8) == 0); |
| 21 | ++ cmp = (ct_memcmp(cksum_data, p + 8, 8) != 0); |
| 22 | + if (cmp) { |
| 23 | + *minor_status = 0; |
| 24 | + return GSS_S_BAD_MIC; |
| 25 | +@@ -730,7 +730,7 @@ OM_uint32 _gssapi_unwrap_arcfour(OM_uint32 *minor_status, |
| 26 | + return GSS_S_FAILURE; |
| 27 | + } |
| 28 | + |
| 29 | +- cmp = (ct_memcmp(cksum_data, p0 + 16, 8) == 0); /* SGN_CKSUM */ |
| 30 | ++ cmp = (ct_memcmp(cksum_data, p0 + 16, 8) != 0); /* SGN_CKSUM */ |
| 31 | + if (cmp) { |
| 32 | + _gsskrb5_release_buffer(minor_status, output_message_buffer); |
| 33 | + *minor_status = 0; |
| 34 | +-- |
| 35 | +2.45.2 |
| 36 | + |
0 commit comments