Re: [PATCH] crypto: qce: fix CCM AAD buffer underallocation
Bartosz Golaszewski <[email protected]>
| Newsgroups | org.kernel.vger.linux-crypto,org.kernel.vger.linux-arm-msm,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAMRc=McDAt5G9-mJSY15oL6vQT+rcOFK0cj+bnx7kk93WooGPQ@mail.gmail.com> |
On Fri, 7 Aug 2026 08:54:54 +0200, Md Sadre Alam <[email protected]> said: > The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() > can be smaller than the length later programmed into the DMA > scatterlist. > > The allocation size is currently calculated as: > > ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN > > while the DMA length is set to: > > ALIGN(assoclen + adata_header_len, 16) > > Since ALIGN() does not distribute over addition, the allocation > can be smaller than the DMA length. For example, when > assoclen = 32 and adata_header_len = 2: > > allocation = ALIGN(32, 16) + 6 = 38 > DMA length = ALIGN(32 + 2, 16) = 48 > > As a result, the QCE hardware can read beyond the allocated > buffer while computing the CBC-MAC over the associated data. > The extra bytes are folded into the authentication tag, > resulting in an incorrect tag and causing CCM self-test > failures such as: > > alg: aead: ccm-aes-qce encryption test failed (wrong result) > on test vector 8 > > Fix the allocation by adding the maximum possible AAD header > length before alignment: > > ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16) > > This guarantees that the allocated buffer is large enough > for the fully padded AAD data for all supported header sizes. > > Cc: [email protected] > Fixes: 9363efb4181c ("crypto: qce - Add support for AEAD algorithms") > Signed-off-by: Md Sadre Alam <[email protected]> > --- Reviewed-by: Bartosz Golaszewski <[email protected]>