From 7796cc4f24245a98a2508f298294c0fc4e6b4577 Mon Sep 17 00:00:00 2001 From: Dave Rodgman Date: Tue, 20 Dec 2022 13:12:23 +0000 Subject: [PATCH 1/2] Fix overflow in mbedtls_timing_hardclock Signed-off-by: Dave Rodgman --- programs/test/benchmark.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/programs/test/benchmark.c b/programs/test/benchmark.c index 6313c522a6..1ad2034d4a 100644 --- a/programs/test/benchmark.c +++ b/programs/test/benchmark.c @@ -398,7 +398,7 @@ static unsigned long mbedtls_timing_hardclock( void ) } gettimeofday( &tv_cur, NULL ); - return( ( tv_cur.tv_sec - tv_init.tv_sec ) * 1000000 + return( ( tv_cur.tv_sec - tv_init.tv_sec ) * 1000000U + ( tv_cur.tv_usec - tv_init.tv_usec ) ); } #endif /* !HAVE_HARDCLOCK */ From 327b69c8a25350c292f89804ffb47a560f585d9b Mon Sep 17 00:00:00 2001 From: Dave Rodgman Date: Tue, 20 Dec 2022 13:16:34 +0000 Subject: [PATCH 2/2] Add Changelog entry Signed-off-by: Dave Rodgman --- ChangeLog.d/fix-gettimeofday-overflow.txt | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 ChangeLog.d/fix-gettimeofday-overflow.txt diff --git a/ChangeLog.d/fix-gettimeofday-overflow.txt b/ChangeLog.d/fix-gettimeofday-overflow.txt new file mode 100644 index 0000000000..b7e10d2b0a --- /dev/null +++ b/ChangeLog.d/fix-gettimeofday-overflow.txt @@ -0,0 +1,3 @@ +Bugfix + * Fix possible integer overflow in mbedtls_timing_hardclock(), which + could cause a crash in programs/test/benchmark.