David Hess’s analysis is correct. This is a bug in the ARM64 assembly for Poly1305, introduced in
https://github.com/openssl/openssl/commit/2cf7fd698ec1375421f91338ff8a44e7da5238b6 (OpenSSL_1_1_1b~37)
and fixed upstream in
https://github.com/openssl/openssl/commit/5795acffd8706e1cb584284ee5bb3a30986d0e75 (OpenSSL_1_1_1i~21).
This fix needs to be backported to focal.
David Hess’s analysis is correct. This is a bug in the ARM64 assembly for Poly1305, introduced in
https:/ /github. com/openssl/ openssl/ commit/ 2cf7fd698ec1375 421f91338ff8a44 e7da5238b6 (OpenSSL_1_1_1b~37)
and fixed upstream in
https:/ /github. com/openssl/ openssl/ commit/ 5795acffd8706e1 cb584284ee5bb3a 30986d0e75 (OpenSSL_ 1_1_1i~ 21).
This fix needs to be backported to focal.