Re: [PATCH v2] crypto: ecc - Handle exceptional points in Shamir multiplication
From: Herbert Xu
Date: Fri Oct 02 2026 - 06:36:16 EST
On Sat, Sep 26, 2026 at 08:43:26PM +0000, Jérémy Jean wrote:
> Shamir multiplication mishandles equal points, opposite points and the
> point at infinity. This rejects valid ECDSA signatures and can accept
> invalid digest/signature tuples when the public key is G or -G. The
> kernel incorrectly rejects 16 valid signatures from Wycheproof.
>
> Handle doubling, cancellation and the point at infinity in precomputation
> and accumulation. Add regression tests for P-256 ECDSA and 256/512-bit
> EC-RDSA. The valid vectors are Wycheproof P1363 secp256r1/SHA-256 cases
> 60 and 210 converted to X9.62, two constructed ECDSA signatures for
> Q = +/-G with k = 2, and six constructed EC-RDSA signatures for Q = G,
> -G and -2G. Also add two invalid P-256 digest/signature tuples for
> Q = +/-G that must return -EKEYREJECTED.
>
> Fixes: 0d7a78643f69 ("crypto: ecrdsa - add EC-RDSA (GOST 34.10) algorithm")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@xxxxxxxxxxxxxxxxx>
> ---
> crypto/ecc.c | 33 ++++-
> crypto/testmgr.c | 11 +-
> crypto/testmgr.h | 327 ++++++++++++++++++++++++++++++++++++++++++++++-
> 3 files changed, 363 insertions(+), 8 deletions(-)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt