From e6e73bc89ebd86a449037e727a1e2f8950f79262 Mon Sep 17 00:00:00 2001 From: Sylvester Kaczmarek <16242628+sylvesterkaczmarek@users.noreply.github.com> Date: Sun, 16 Aug 2026 16:12:33 +0100 Subject: [PATCH] Fix #522, avoid unsupported IVs for ACS MACs --- ...ryptography_interface_libgcrypt.template.c | 30 +++---------------- 1 file changed, 4 insertions(+), 26 deletions(-) diff --git a/src/crypto/libgcrypt/cryptography_interface_libgcrypt.template.c b/src/crypto/libgcrypt/cryptography_interface_libgcrypt.template.c index 2fa5ee06..9cfb0a3a 100644 --- a/src/crypto/libgcrypt/cryptography_interface_libgcrypt.template.c +++ b/src/crypto/libgcrypt/cryptography_interface_libgcrypt.template.c @@ -130,6 +130,8 @@ static int32_t cryptography_authenticate( } // Using to fix warning len_data_out = len_data_out; + iv = iv; + iv_len = iv_len; ecs = ecs; cam_cookies = cam_cookies; @@ -168,19 +170,6 @@ static int32_t cryptography_authenticate( return status; } - // If MAC needs IV, set it (only for certain ciphers) - if (iv_len > 0) - { - gcry_error = gcry_mac_setiv(tmp_mac_hd, iv, iv_len); - if ((gcry_error & GPG_ERR_CODE_MASK) != GPG_ERR_NO_ERROR) - { - printf(KRED "ERROR: gcry_mac_setiv error code %d\n" RESET, gcry_error & GPG_ERR_CODE_MASK); - printf(KRED "Failure: %s/%s\n", gcry_strsource(gcry_error), gcry_strerror(gcry_error)); - status = CRYPTO_LIB_ERROR; - gcry_mac_close(tmp_mac_hd); - return status; - } - } gcry_error = gcry_mac_write(tmp_mac_hd, aad, // additional authenticated data @@ -240,6 +229,8 @@ static int32_t cryptography_validate_authentication(uint8_t *data_out, size_t le return CRYPTO_LIB_ERR_NULL_BUFFER; } // Using to fix warning + iv = iv; + iv_len = iv_len; ecs = ecs; cam_cookies = cam_cookies; @@ -277,19 +268,6 @@ static int32_t cryptography_validate_authentication(uint8_t *data_out, size_t le status = CRYPTO_LIB_ERR_LIBGCRYPT_ERROR; return status; } - // If MAC needs IV, set it (only for certain ciphers) - if (iv_len > 0) - { - gcry_error = gcry_mac_setiv(tmp_mac_hd, iv, iv_len); - if ((gcry_error & GPG_ERR_CODE_MASK) != GPG_ERR_NO_ERROR) - { - printf(KRED "ERROR: gcry_mac_setiv error code %d\n" RESET, gcry_error & GPG_ERR_CODE_MASK); - printf(KRED "Failure: %s/%s\n" RESET, gcry_strsource(gcry_error), gcry_strerror(gcry_error)); - gcry_mac_close(tmp_mac_hd); - status = CRYPTO_LIB_ERROR; - return status; - } - } gcry_error = gcry_mac_write(tmp_mac_hd, aad, // additional authenticated data aad_len // length of AAD