mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 08:45:18 -04:00
crypto: sa2ul - use crypto_memneq() to compare AEAD tag
Use crypto_memneq() for a constant-time comparison. sa_aead_dma_in_callback() compares the computed authentication tag against the received tag with memcmp(), which short-circuits on the first differing byte. An attacker who can submit decrypt requests and observe completion latency could recover the expected tag byte by byte. Valid tag forgery for AEAD breaks the INT-CTXT guarantee. Assisted-by: gregkh_clanker_t1000 Signed-off-by: David C.C.M. Gall <david.ccm.gall@googlemail.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This commit is contained in:
committed by
Herbert Xu
parent
528bc53c3b
commit
7064af16d2
@@ -22,6 +22,7 @@
|
||||
|
||||
#include <crypto/aes.h>
|
||||
#include <crypto/authenc.h>
|
||||
#include <crypto/utils.h>
|
||||
#include <crypto/des.h>
|
||||
#include <crypto/internal/aead.h>
|
||||
#include <crypto/internal/hash.h>
|
||||
@@ -1688,7 +1689,7 @@ static void sa_aead_dma_in_callback(void *data)
|
||||
scatterwalk_map_and_copy(auth_tag, req->src, start, authsize,
|
||||
0);
|
||||
|
||||
err = memcmp(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0;
|
||||
err = crypto_memneq(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0;
|
||||
}
|
||||
|
||||
sa_free_sa_rx_data(rxd);
|
||||
|
||||
Reference in New Issue
Block a user