Re: [PATCH] crypto: ecc - Handle exceptional points in Shamir multiplication

From: Jérémy Jean

Date: Sat Sep 26 2026 - 16:18:15 EST


On 2026-09-26 16:17, Ignat Korchagin wrote:
On Fri, Sep 25, 2026 at 2:23 PM Jérémy Jean
<Jeremy.Jean@xxxxxxxxxxxxxxxxx> wrote:

Shamir multiplication mishandles equal points, opposite points and the
point at infinity. This rejects valid ECDSA signatures and can accept
invalid digest/signature tuples when the public key is G or -G. The

Can you provide/construct test vectors for these? The ones that were
accepted, but should fail.

Hello Ignat,

Thanks for the answer.
Good idea, I will add some in a v2.

Jérémy