Re: Continuing with: Account request + libgcrypt security finding

Werner Koch via Gcrypt-devel <[email protected]> Thu, 16 Apr 2026 10:36:27 +0200
Newsgroups gmane.comp.encryption.gpg.libgcrypt.devel
Message-ID <[email protected]>
--===============4821531517006059117==
Content-Type: multipart/signed; boundary="=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale";
	micalg=pgp-sha512; protocol="application/pgp-signature"

--=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Hi!

On Wed, 15 Apr 2026 13:54, Bert van der Weerd said:

> In non-FIPS mode, _if_ the caller never invokes set_iv() before
> calling gcm_encrypt(), gcm_decrypt(), or gcm_authenticate(), the
> library does not return an error.

GCM aas well as all other counter modes are pretty fragile and tehre are
a lot of conditions which lead to catastrophic failures.  So better
avoid GCM and use a robust mode like OCB.

I do not considere this a bug becuase it is improper use of the
algorithms.  Right, we may check whether set_iv has been used but it
won't be possible to check for nonce re-use - that is the caller's duty.

Let us open a feature request to return a GPG_ERR_MISSING_ACTION error
if set_iv has not been used.


Salam-Shalom,

   Werner

=2D-=20
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

--=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale
Content-Type: application/pgp-signature; name="openpgp-digital-signature.asc"

-----BEGIN PGP SIGNATURE-----

iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCaeCfixsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMSwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQej32AQDV
bvyN+Ij+bde+DkPC/P/eQNZcl9306D107UCB0Bx6HAD+O2uyG4wyPzPo+N/Nzo1e
nuup0P2o0qfJPZH2Vzf68AU=
=tn29
-----END PGP SIGNATURE-----
--=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale--



--===============4821531517006059117==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gcrypt-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gcrypt-devel

--===============4821531517006059117==--