Commit Graph
7 Commits
Author SHA1 Message Date
Tobias Brunner 1b9b037816 sha3: Fix applying second padding bit on big-endian platforms
Fixes: 56f4b2096a ("sha3: Fix Keccak when compiled with GCC 13.x")
2026-07-24 08:47:39 +02:00
Tobias Brunner 4224c3f647 sha3: Make sure state and rate input buffers are 8-byte aligned
Both buffers are accessed directly by casting to `uint64_t`.  On platforms
that don't allow unaligned accesses this could cause a SIGBUS.  The
reorder should avoid extra padding between the two buffers.

Fixes: 5ff88c9622 ("xof: Implemented SHAKE128 and SHAKE256 Extended Output Functions")
Fixes: 83c1883d0b ("Use word-aligned XOR in sha3_absorb()")
2026-07-24 08:47:38 +02:00
Tobias Brunner 56f4b2096a sha3: Fix Keccak when compiled with GCC 13.x
With GCC 13, the compiler apparently applies new aliasing optimizations
when compiled with -O2 and without -fno-strict-aliasing.  This caused
the application of the second padding bit, where the state was accessed
via uint8_t[], to be moved before the loop that absorbs the buffer into
the state, where the state is accessed via uint64_t[], resulting in
incorrect output.  By only accessing the state via uint64_t[] here the
compiler won't reorder the instructions.
2024-04-02 14:19:40 +02:00
Tobias Brunner e0e99c1dd3 sha3: Make sure to wipe the internal Keccak state 2023-07-26 15:08:33 +02:00
Tobias Brunner 19ef2aec15 Update copyright headers after acquisition by secunet 2022-06-28 10:22:56 +02:00
Tobias Brunner 3bc0c9807a sha3: Fix readLane() macro on big-endian platforms 2020-01-20 11:05:17 +01:00
Andreas Steffen 5ff88c9622 xof: Implemented SHAKE128 and SHAKE256 Extended Output Functions 2016-07-29 12:36:14 +02:00