diff options
| author | David C.C.M. Gall <david.ccm.gall@googlemail.com> | 2026-08-07 18:22:00 +0200 |
|---|---|---|
| committer | Herbert Xu <herbert@gondor.apana.org.au> | 2026-08-15 11:28:36 +1000 |
| commit | ff2ac77a034e03b64e2ba34f775097427dfa5547 (patch) | |
| tree | 1314fe35e90f0ff18390ba26b052edd25263a6ad /drivers | |
| parent | 353b3a85136f2a0cf3e872acf8ad6c1dec0b7a8e (diff) | |
crypto: keembay - use crypto_memneq() to compare CCM AEAD tags
Use crypto_memneq() for constant-time comparison.
The CCM path in ocs-aes.c verifes the received authentication tag with
memcmp(), which returns early on the first mismatched byte. This leaks
valid-prefix length and allows for valid tag forgery which violates the
INT-CTXT guarantee of AEAD.
Assisted-by: gregkh_clanker_t1000
Signed-off-by: David C.C.M. Gall <david.ccm.gall@googlemail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Diffstat (limited to 'drivers')
| -rw-r--r-- | drivers/crypto/intel/keembay/ocs-aes.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/drivers/crypto/intel/keembay/ocs-aes.c b/drivers/crypto/intel/keembay/ocs-aes.c index bb6f33f6b4d3..13ba7573617f 100644 --- a/drivers/crypto/intel/keembay/ocs-aes.c +++ b/drivers/crypto/intel/keembay/ocs-aes.c @@ -17,6 +17,7 @@ #include <crypto/aes.h> #include <crypto/gcm.h> +#include <crypto/utils.h> #include "ocs-aes.h" @@ -1283,7 +1284,7 @@ static inline int ccm_compare_tag_to_yr(struct ocs_aes_dev *aes_dev, (i * sizeof(u32))); } - return memcmp(tag, yr, tag_size_bytes) ? -EBADMSG : 0; + return crypto_memneq(tag, yr, tag_size_bytes) ? -EBADMSG : 0; } /** |
