diff --git a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c index 026dd23ae08..3a888e9c8f1 100644 --- a/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c +++ b/components/esp_tee/subproject/components/tee_sec_storage/tee_sec_storage.c @@ -572,17 +572,8 @@ esp_err_t esp_tee_sec_storage_ecdsa_get_pubkey(const esp_tee_sec_storage_key_cfg return ESP_ERR_INVALID_ARG; } - // If pub_key_src[0] is 0x04, then it is compressed format - // This is what we save when exporting the public key from PSA - if (pub_key_src[0] == 0x04) { - memcpy(out_pubkey->pub_x, pub_key_src + 1, pub_key_len); - memcpy(out_pubkey->pub_y, pub_key_src + pub_key_len + 1, pub_key_len); - } else { - // This case is when the keys are host generated - // In this case the public key is stored as X and Y concatenated without 0x04 prefix - memcpy(out_pubkey->pub_x, pub_key_src, pub_key_len); - memcpy(out_pubkey->pub_y, pub_key_src + pub_key_len, pub_key_len); - } + memcpy(out_pubkey->pub_x, pub_key_src, pub_key_len); + memcpy(out_pubkey->pub_y, pub_key_src + pub_key_len, pub_key_len); return ESP_OK; } diff --git a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c index f8311cf8af4..ad18760de11 100644 --- a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c +++ b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes.c @@ -488,6 +488,7 @@ static psa_status_t esp_crypto_aes_setup( status = mbedtls_to_psa_error(esp_aes_setkey(ctx, key_buffer, key_buffer_size * 8)); if (status != PSA_SUCCESS) { + free(ctx); goto exit; } diff --git a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c index f15d0c35d43..7ccf1b1dc98 100644 --- a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c +++ b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_aes_gcm.c @@ -25,6 +25,7 @@ static psa_status_t esp_crypto_aes_gcm_setup( psa_algorithm_t alg, psa_encrypt_or_decrypt_t mode) { psa_status_t status = PSA_ERROR_GENERIC_ERROR; + esp_gcm_context *ctx = NULL; if (alg != PSA_ALG_GCM) { status = PSA_ERROR_NOT_SUPPORTED; @@ -36,7 +37,7 @@ static psa_status_t esp_crypto_aes_gcm_setup( goto exit; } - esp_gcm_context *ctx = (esp_gcm_context *) malloc(sizeof(esp_gcm_context)); + ctx = (esp_gcm_context *) malloc(sizeof(esp_gcm_context)); if (ctx == NULL) { status = PSA_ERROR_INSUFFICIENT_MEMORY; goto exit; @@ -47,6 +48,7 @@ static psa_status_t esp_crypto_aes_gcm_setup( status = mbedtls_to_psa_error(esp_aes_gcm_setkey(ctx, 2, key_buffer, key_buffer_size * 8)); if (status != PSA_SUCCESS) { + free(ctx); goto exit; } diff --git a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_cmac.c b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_cmac.c index 4eb73324fd7..94b4f3ed125 100644 --- a/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_cmac.c +++ b/components/mbedtls/port/psa_driver/esp_aes/psa_crypto_driver_esp_cmac.c @@ -210,6 +210,7 @@ psa_status_t esp_cmac_mac_setup(esp_cmac_operation_t *operation, status = esp_sha_hash_compute(hash_alg, key_buffer, key_buffer_size, ipad, sizeof(ipad), &key_buffer_size); if (status != PSA_SUCCESS) { + return status; } } /* A 0-length key is not commonly used in HMAC when used as a MAC, @@ -602,7 +603,7 @@ psa_status_t esp_cmac_mac_verify_finish( size_t actual_mac_length = 0; - status = esp_cmac_mac_finish(operation, actual_mac, mac_length, &actual_mac_length); + status = esp_cmac_mac_finish(operation, actual_mac, sizeof(actual_mac), &actual_mac_length); if (status == PSA_SUCCESS) { if (memcmp(actual_mac, mac, mac_length) == 0) { return PSA_SUCCESS; diff --git a/components/mbedtls/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c b/components/mbedtls/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c index 296fad8212d..0bf0a75a231 100644 --- a/components/mbedtls/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c +++ b/components/mbedtls/port/psa_driver/esp_sha/psa_crypto_driver_esp_sha.c @@ -136,11 +136,13 @@ psa_status_t esp_sha_hash_setup(esp_sha_hash_operation_t *operation, psa_algorit } memset(sha256_ctx, 0, sizeof(esp_sha256_context)); operation->sha_ctx = sha256_ctx; - int mode = SHA2_256; - operation->sha_type = ESP_SHA_OPERATION_TYPE_SHA256; + int mode; #if CONFIG_SOC_SHA_SUPPORT_SHA224 operation->sha_type = (alg == PSA_ALG_SHA_224) ? ESP_SHA_OPERATION_TYPE_SHA224 : ESP_SHA_OPERATION_TYPE_SHA256; mode = (alg == PSA_ALG_SHA_224) ? SHA2_224 : SHA2_256; +#else + operation->sha_type = ESP_SHA_OPERATION_TYPE_SHA256; + mode = SHA2_256; #endif // CONFIG_SOC_SHA_SUPPORT_SHA224 return esp_sha256_starts(sha256_ctx, mode); } else diff --git a/components/protocomm/src/crypto/srp6a/esp_srp.c b/components/protocomm/src/crypto/srp6a/esp_srp.c index 9636931f06f..1ae4aa80022 100644 --- a/components/protocomm/src/crypto/srp6a/esp_srp.c +++ b/components/protocomm/src/crypto/srp6a/esp_srp.c @@ -678,7 +678,7 @@ esp_err_t esp_srp_get_session_key(esp_srp_handle_t *hd, char *bytes_A, int len_A psa_hash_operation_t hash_op = PSA_HASH_OPERATION_INIT; psa_status_t status = psa_hash_setup(&hash_op, PSA_ALG_SHA_512); - ESP_RETURN_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, TAG, "Failed to setup hash operation: %d", status); + ESP_GOTO_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, error, TAG, "Failed to setup hash operation: %d", status); psa_hash_update(&hash_op, (unsigned char *)bytes_S, len_S); size_t hash_len = 0; status = psa_hash_finish(&hash_op, (unsigned char *)hd->session_key, SHA512_HASH_SZ, &hash_len); diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-bignum.c b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-bignum.c index 72db92622a5..751b59149d1 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-bignum.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-bignum.c @@ -38,10 +38,12 @@ struct crypto_bignum *crypto_bignum_init_set(const u8 *buf, size_t len) return NULL; } + mbedtls_mpi_init(bn); MBEDTLS_MPI_CHK(mbedtls_mpi_read_binary(bn, buf, len)); return (struct crypto_bignum *) bn; cleanup: + mbedtls_mpi_free(bn); os_free(bn); return NULL; } diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c index f31614d559b..271654c8a35 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls-ec.c @@ -1008,9 +1008,14 @@ int crypto_ec_get_publickey_buf(struct crypto_ec_key *key, u8 *key_buf, int len) if (!wrapper) { return -1; } + + if (key_buf == NULL && len != 0) { + return -1; + } + psa_status_t status = PSA_SUCCESS; - if (key_buf == NULL && len == 0) { + if (key_buf == NULL) { // This is a call to determine the buffer length // needed for the public key @@ -1743,6 +1748,7 @@ struct crypto_ecdh * crypto_ecdh_init(int group) psa_ecc_family_t ecc_family = group_id_to_psa(crypto_mbedtls_get_grp_id(group), &key_size); if (ecc_family == 0) { + os_free(key_id); wpa_printf(MSG_ERROR, "group_id_to_psa failed, group: %d", group); return NULL; } diff --git a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c index 2d09d1aa7b1..107ac6172d3 100644 --- a/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c +++ b/components/wpa_supplicant/esp_supplicant/src/crypto/crypto_mbedtls.c @@ -248,8 +248,7 @@ int crypto_hash_finish(struct crypto_hash *crypto_ctx, u8 *mac, size_t *len) int ret = 0; if (crypto_ctx == NULL) { - ret = -2; - goto err; + return -2; } if (mac == NULL || len == NULL) { @@ -715,14 +714,14 @@ struct crypto_cipher *crypto_cipher_init(enum crypto_cipher_alg alg, uint32_t psa_alg = alg_to_psa_cipher(alg); if (psa_alg == 0) { wpa_printf(MSG_ERROR, "%s: invalid cipher algorithm", __func__); - return NULL; + goto cleanup; } psa_set_key_algorithm(&attributes, psa_alg); uint32_t psa_key_type = alg_to_psa_key_type(alg); if (psa_key_type == 0) { wpa_printf(MSG_ERROR, "%s: invalid key type", __func__); - return NULL; + goto cleanup; } psa_set_key_type(&attributes, psa_key_type); psa_set_key_bits(&attributes, key_len * 8); @@ -730,7 +729,7 @@ struct crypto_cipher *crypto_cipher_init(enum crypto_cipher_alg alg, status = psa_import_key(&attributes, key, key_len, &key_id); if (status != PSA_SUCCESS) { wpa_printf(MSG_ERROR, "%s: psa_import_key failed", __func__); - return NULL; + goto cleanup; } psa_reset_key_attributes(&attributes);