From: Dr. Stephen Henson Date: Mon, 15 Feb 2010 19:40:16 +0000 (+0000) Subject: The "block length" for CFB mode was incorrectly coded as 1 all the time. It X-Git-Tag: OpenSSL-fips-2_0-rc1~1269 X-Git-Url: https://git.openssl.org/?p=openssl.git;a=commitdiff_plain;h=1458b931ebfd9973643dc57e7d02a71749d0b910;ds=sidebyside The "block length" for CFB mode was incorrectly coded as 1 all the time. It should be the number of feedback bits expressed in bytes. For CFB1 mode set this to 1 by rounding up to the nearest multiple of 8. --- diff --git a/crypto/evp/evp_locl.h b/crypto/evp/evp_locl.h index 1b6c811fd6..ff0f3c1a8e 100644 --- a/crypto/evp/evp_locl.h +++ b/crypto/evp/evp_locl.h @@ -155,9 +155,9 @@ BLOCK_CIPHER_def1(cname, cbc, cbc, CBC, kstruct, nid, block_size, key_len, \ #define BLOCK_CIPHER_def_cfb(cname, kstruct, nid, key_len, \ iv_len, cbits, flags, init_key, cleanup, \ set_asn1, get_asn1, ctrl) \ -BLOCK_CIPHER_def1(cname, cfb##cbits, cfb##cbits, CFB, kstruct, nid, 1, \ - key_len, iv_len, flags, init_key, cleanup, set_asn1, \ - get_asn1, ctrl) +BLOCK_CIPHER_def1(cname, cfb##cbits, cfb##cbits, CFB, kstruct, nid, \ + (cbits + 7)/8, key_len, iv_len, \ + flags, init_key, cleanup, set_asn1, get_asn1, ctrl) #define BLOCK_CIPHER_def_ofb(cname, kstruct, nid, key_len, \ iv_len, cbits, flags, init_key, cleanup, \