Blame SOURCES/0046-FIPS-s390x-hardening.patch

a74baf
diff --git a/crypto/ec/ecp_s390x_nistp.c b/crypto/ec/ecp_s390x_nistp.c
a74baf
index 5c70b2d67840..c5726c638bdd 100644
a74baf
--- a/crypto/ec/ecp_s390x_nistp.c
a74baf
+++ b/crypto/ec/ecp_s390x_nistp.c
a74baf
@@ -116,7 +116,7 @@ static int ec_GFp_s390x_nistp_mul(const EC_GROUP *group, EC_POINT *r,
a74baf
     /* Otherwise use default. */
a74baf
     if (rc == -1)
a74baf
         rc = ossl_ec_wNAF_mul(group, r, scalar, num, points, scalars, ctx);
a74baf
-    OPENSSL_cleanse(param + S390X_OFF_SCALAR(len), len);
a74baf
+    OPENSSL_cleanse(param, sizeof(param));
a74baf
     BN_CTX_end(ctx);
a74baf
     BN_CTX_free(new_ctx);
a74baf
     return rc;
a74baf
@@ -212,7 +212,7 @@ static ECDSA_SIG *ecdsa_s390x_nistp_sign_sig(const unsigned char *dgst,
a74baf
 
a74baf
     ok = 1;
a74baf
 ret:
a74baf
-    OPENSSL_cleanse(param + S390X_OFF_K(len), 2 * len);
a74baf
+    OPENSSL_cleanse(param, sizeof(param));
a74baf
     if (ok != 1) {
a74baf
         ECDSA_SIG_free(sig);
a74baf
         sig = NULL;