[PATCH] crypto: sa2ul - use crypto_memneq() to compare AEAD tag
"David C.C.M. Gall" <[email protected]>
| Newsgroups | org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <anX9UKJ66Aak4ICV@fudgebox> |
Use crypto_memneq() for a constant-time comparison. sa_aead_dma_in_callback() compares the computed authentication tag against the received tag with memcmp(), which short-circuits on the first differing byte. An attacker who can submit decrypt requests and observe completion latency could recover the expected tag byte by byte. Valid tag forgery for AEAD breaks the INT-CTXT guarantee. Assisted-by: gregkh_clanker_t1000 Signed-off-by: David C.C.M. Gall <[email protected]> --- drivers/crypto/sa2ul.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c index 965a03d5b27a..7cdfc91670f7 100644 --- a/drivers/crypto/sa2ul.c +++ b/drivers/crypto/sa2ul.c @@ -22,6 +22,7 @@ #include <crypto/aes.h> #include <crypto/authenc.h> +#include <crypto/utils.h> #include <crypto/des.h> #include <crypto/internal/aead.h> #include <crypto/internal/hash.h> @@ -1688,7 +1689,7 @@ static void sa_aead_dma_in_callback(void *data) scatterwalk_map_and_copy(auth_tag, req->src, start, authsize, 0); - err = memcmp(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0; + err = crypto_memneq(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0; } sa_free_sa_rx_data(rxd); -- 2.43.0