[PATCH 2/2] crypto: keembay - use crypto_memneq() to compare CCM AEAD tags
"David C.C.M. Gall" <[email protected]>
| Newsgroups | org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
Use crypto_memneq() for constant-time comparison. The CCM path in ocs-aes.c verifes the received authentication tag with memcmp(), which returns early on the first mismatched byte. This leaks valid-prefix length and allows for valid tag forgery which violates the INT-CTXT guarantee of AEAD. Assisted-by: gregkh_clanker_t1000 Signed-off-by: David C.C.M. Gall <[email protected]> --- drivers/crypto/intel/keembay/ocs-aes.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/crypto/intel/keembay/ocs-aes.c b/drivers/crypto/intel/keembay/ocs-aes.c index bb6f33f6b4d3..13ba7573617f 100644 --- a/drivers/crypto/intel/keembay/ocs-aes.c +++ b/drivers/crypto/intel/keembay/ocs-aes.c @@ -17,6 +17,7 @@ #include <crypto/aes.h> #include <crypto/gcm.h> +#include <crypto/utils.h> #include "ocs-aes.h" @@ -1283,7 +1284,7 @@ static inline int ccm_compare_tag_to_yr(struct ocs_aes_dev *aes_dev, (i * sizeof(u32))); } - return memcmp(tag, yr, tag_size_bytes) ? -EBADMSG : 0; + return crypto_memneq(tag, yr, tag_size_bytes) ? -EBADMSG : 0; } /** -- 2.43.0