mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sabrina Dubroca <sd@queasysnail.net>
To: "Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org
Subject: Re: [PATCH net] macsec: prevent AES-GCM nonce reuse after packet number wrap
Date: Thu, 1 Oct 2026 11:43:07 +0200	[thread overview]
Message-ID: <ar4rKxYd7Csm6l2t@krikkit> (raw)
In-Reply-To: <20260930203333.598733-2-Jeremy.Jean@oss.cyber.gouv.fr>

2026-09-30, 20:33:33 +0000, Jérémy Jean wrote:
> When MACsec uses 32-bit packet numbers, 0xffffffff is the last valid
> packet number

This makes it sound like it's only a problem for 32b packet numbers,
but I think it affects both? Sure it's unlikely with 64b unless we
start from a large offset, but a well-behaved userspace should also
rekey and switch SAs before we ever wrap to avoid losing packets while
the rekey completes (but yes, "losing packets" is not as bad as
"breaking crypto").

> and after allocating it, MACsec deactivates the
> transmit SA and wraps the next packet number to zero. Packets already
> in flight can still be processed after that.

So this is more of a race condition than a full "forever" bug. I think
commit messages should be clear about that (and that doesn't mean it's
not bad or not worth patching, but it's worth mentioning).

Once TX operations hit macsec_encrypt -> macsec_txsa_get and see
!sa->active, packets will be dropped and nonce reuse stops.


> The first late packet gets packet number zero and is dropped, but
> tx_sa_update_pn() has already advanced the stored counter to one before
> macsec_encrypt() drops it. A second late packet can then be sent with
> packet number one again, reusing the AES-GCM nonce from the start of the
> SA.
>
> Keep next_pn at zero after wrap so all late packets are dropped.

"late packet" is defined on the RX side, but it doesn't make sense on
the TX path.

The diff looks good to me.

-- 
Sabrina

      parent reply	other threads:[~2026-10-01  9:43 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 20:33 Jérémy Jean
2026-09-30 20:38 ` netdev-bot+sinfo
2026-10-01  9:43 ` Sabrina Dubroca [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ar4rKxYd7Csm6l2t@krikkit \
    --to=sd@queasysnail.net \
    --cc=Jeremy.Jean@oss.cyber.gouv.fr \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®