crypto: sa2ul - use crypto_memneq() to compare AEAD tag

Use crypto_memneq() for a constant-time comparison.

sa_aead_dma_in_callback() compares the computed authentication tag
against the received tag with memcmp(), which short-circuits on the
first differing byte. An attacker who can submit decrypt requests and
observe completion latency could recover the expected tag byte by byte.

Valid tag forgery for AEAD breaks the INT-CTXT guarantee.

Assisted-by: gregkh_clanker_t1000
Signed-off-by: David C.C.M. Gall <david.ccm.gall@googlemail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This commit is contained in:
David C.C.M. Gall
2026-08-07 17:44:16 +02:00
committed by Herbert Xu
parent 528bc53c3b
commit 7064af16d2

View File

@@ -22,6 +22,7 @@
#include <crypto/aes.h>
#include <crypto/authenc.h>
#include <crypto/utils.h>
#include <crypto/des.h>
#include <crypto/internal/aead.h>
#include <crypto/internal/hash.h>
@@ -1688,7 +1689,7 @@ static void sa_aead_dma_in_callback(void *data)
scatterwalk_map_and_copy(auth_tag, req->src, start, authsize,
0);
err = memcmp(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0;
err = crypto_memneq(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0;
}
sa_free_sa_rx_data(rxd);