Re: Continuing with: Account request + libgcrypt security finding
Werner Koch via Gcrypt-devel <[email protected]> Thu, 16 Apr 2026 10:36:27 +0200
| Newsgroups | gmane.comp.encryption.gpg.libgcrypt.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============4821531517006059117== Content-Type: multipart/signed; boundary="=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale"; micalg=pgp-sha512; protocol="application/pgp-signature" --=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hi! On Wed, 15 Apr 2026 13:54, Bert van der Weerd said: > In non-FIPS mode, _if_ the caller never invokes set_iv() before > calling gcm_encrypt(), gcm_decrypt(), or gcm_authenticate(), the > library does not return an error. GCM aas well as all other counter modes are pretty fragile and tehre are a lot of conditions which lead to catastrophic failures. So better avoid GCM and use a robust mode like OCB. I do not considere this a bug becuase it is improper use of the algorithms. Right, we may check whether set_iv has been used but it won't be possible to check for nonce re-use - that is the caller's duty. Let us open a feature request to return a GPG_ERR_MISSING_ACTION error if set_iv has not been used. Salam-Shalom, Werner =2D-=20 The pioneers of a warless world are the youth that refuse military service. - A. Einstein --=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale Content-Type: application/pgp-signature; name="openpgp-digital-signature.asc" -----BEGIN PGP SIGNATURE----- iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCaeCfixsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMSwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQej32AQDV bvyN+Ij+bde+DkPC/P/eQNZcl9306D107UCB0Bx6HAD+O2uyG4wyPzPo+N/Nzo1e nuup0P2o0qfJPZH2Vzf68AU= =tn29 -----END PGP SIGNATURE----- --=Lebed_Fort_Meade_Mavricks_AIEWS_al-Qaida_CIA_9/11_Armani_INSCOM_Tale-- --===============4821531517006059117== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Gcrypt-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gcrypt-devel --===============4821531517006059117==--