Re: [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag
[email protected] Thu, 23 Jul 2026 15:20:15 +0000
| Newsgroups | org.kernel.vger.linux-wpan,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable |
|---|---|
| Message-ID | <178482001540.2315735.1412808647619439700.git-patchwork-notify@kernel.org> |
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <[email protected]>: On Thu, 16 Jul 2026 21:34:23 +0200 you wrote: > llsec_do_decrypt_auth() computes the associated-data length for the > AEAD request as > > assoclen += datalen - authlen; > > where datalen is the number of bytes after the MAC header and authlen > (4, 8 or 16) is the length of the authentication tag. Nothing verifies > that the frame actually carries at least authlen payload bytes. A > secured frame whose payload is shorter than the tag makes > datalen - authlen negative; assoclen is then passed to > aead_request_set_ad() as an unsigned value close to 4 GiB, so > crypto_aead_decrypt() walks far off the end of the scatterlist that > only spans the real frame. > > [...] Here is the summary with links: - [net,v2] mac802154: llsec: reject frames shorter than the authentication tag https://git.kernel.org/netdev/net/c/fd3a3f28ed60 You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html