* [PATCH] crypto: sa2ul - use crypto_memneq() to compare AEAD tag
@ 2026-08-07 15:44 David C.C.M. Gall
2026-08-15 1:31 ` Herbert Xu
0 siblings, 1 reply; 2+ messages in thread
From: David C.C.M. Gall @ 2026-08-07 15:44 UTC (permalink / raw)
To: Herbert Xu, David S. Miller, linux-crypto, linux-kernel; +Cc: gregkh
Use crypto_memneq() for a constant-time comparison.
sa_aead_dma_in_callback() compares the computed authentication tag
against the received tag with memcmp(), which short-circuits on the
first differing byte. An attacker who can submit decrypt requests and
observe completion latency could recover the expected tag byte by byte.
Valid tag forgery for AEAD breaks the INT-CTXT guarantee.
Assisted-by: gregkh_clanker_t1000
Signed-off-by: David C.C.M. Gall <david.ccm.gall@googlemail.com>
---
drivers/crypto/sa2ul.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 965a03d5b27a..7cdfc91670f7 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -22,6 +22,7 @@
#include <crypto/aes.h>
#include <crypto/authenc.h>
+#include <crypto/utils.h>
#include <crypto/des.h>
#include <crypto/internal/aead.h>
#include <crypto/internal/hash.h>
@@ -1688,7 +1689,7 @@ static void sa_aead_dma_in_callback(void *data)
scatterwalk_map_and_copy(auth_tag, req->src, start, authsize,
0);
- err = memcmp(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0;
+ err = crypto_memneq(&mdptr[4], auth_tag, authsize) ? -EBADMSG : 0;
}
sa_free_sa_rx_data(rxd);
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] crypto: sa2ul - use crypto_memneq() to compare AEAD tag
2026-08-07 15:44 [PATCH] crypto: sa2ul - use crypto_memneq() to compare AEAD tag David C.C.M. Gall
@ 2026-08-15 1:31 ` Herbert Xu
0 siblings, 0 replies; 2+ messages in thread
From: Herbert Xu @ 2026-08-15 1:31 UTC (permalink / raw)
To: David C.C.M. Gall; +Cc: David S. Miller, linux-crypto, linux-kernel, gregkh
On Fri, Aug 07, 2026 at 05:44:16PM +0200, David C.C.M. Gall wrote:
> Use crypto_memneq() for a constant-time comparison.
>
> sa_aead_dma_in_callback() compares the computed authentication tag
> against the received tag with memcmp(), which short-circuits on the
> first differing byte. An attacker who can submit decrypt requests and
> observe completion latency could recover the expected tag byte by byte.
>
> Valid tag forgery for AEAD breaks the INT-CTXT guarantee.
>
> Assisted-by: gregkh_clanker_t1000
> Signed-off-by: David C.C.M. Gall <david.ccm.gall@googlemail.com>
> ---
> drivers/crypto/sa2ul.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-15 1:31 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-07 15:44 [PATCH] crypto: sa2ul - use crypto_memneq() to compare AEAD tag David C.C.M. Gall
2026-08-15 1:31 ` Herbert Xu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®