All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Jason A. Donenfeld" <Jason@zx2c4.com>
To: linux-kernel@vger.kernel.org, kernel-hardening@lists.openwall.com
Cc: "Jason A. Donenfeld" <Jason@zx2c4.com>,
	Johannes Berg <johannes@sipsolutions.net>,
	linux-wireless@vger.kernel.org, stable@vger.kernel.org
Subject: [kernel-hardening] [PATCH 6/6] mac80211/wpa: use constant time memory comparison for MACs
Date: Sat, 10 Jun 2017 04:59:12 +0200	[thread overview]
Message-ID: <20170610025912.6499-7-Jason@zx2c4.com> (raw)
In-Reply-To: <20170610025912.6499-1-Jason@zx2c4.com>

Otherwise, we enable all sorts of forgeries via timing attack.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Cc: Johannes Berg <johannes@sipsolutions.net>
Cc: linux-wireless@vger.kernel.org
Cc: stable@vger.kernel.org
---
 net/mac80211/wpa.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/net/mac80211/wpa.c b/net/mac80211/wpa.c
index c1ef22df865f..cc19614ff4e6 100644
--- a/net/mac80211/wpa.c
+++ b/net/mac80211/wpa.c
@@ -17,6 +17,7 @@
 #include <asm/unaligned.h>
 #include <net/mac80211.h>
 #include <crypto/aes.h>
+#include <crypto/algapi.h>
 
 #include "ieee80211_i.h"
 #include "michael.h"
@@ -153,7 +154,7 @@ ieee80211_rx_h_michael_mic_verify(struct ieee80211_rx_data *rx)
 	data_len = skb->len - hdrlen - MICHAEL_MIC_LEN;
 	key = &rx->key->conf.key[NL80211_TKIP_DATA_OFFSET_RX_MIC_KEY];
 	michael_mic(key, hdr, data, data_len, mic);
-	if (memcmp(mic, data + data_len, MICHAEL_MIC_LEN) != 0)
+	if (crypto_memneq(mic, data + data_len, MICHAEL_MIC_LEN))
 		goto mic_fail;
 
 	/* remove Michael MIC from payload */
@@ -1048,7 +1049,7 @@ ieee80211_crypto_aes_cmac_decrypt(struct ieee80211_rx_data *rx)
 		bip_aad(skb, aad);
 		ieee80211_aes_cmac(key->u.aes_cmac.tfm, aad,
 				   skb->data + 24, skb->len - 24, mic);
-		if (memcmp(mic, mmie->mic, sizeof(mmie->mic)) != 0) {
+		if (crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
 			key->u.aes_cmac.icverrors++;
 			return RX_DROP_UNUSABLE;
 		}
@@ -1098,7 +1099,7 @@ ieee80211_crypto_aes_cmac_256_decrypt(struct ieee80211_rx_data *rx)
 		bip_aad(skb, aad);
 		ieee80211_aes_cmac_256(key->u.aes_cmac.tfm, aad,
 				       skb->data + 24, skb->len - 24, mic);
-		if (memcmp(mic, mmie->mic, sizeof(mmie->mic)) != 0) {
+		if (crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
 			key->u.aes_cmac.icverrors++;
 			return RX_DROP_UNUSABLE;
 		}
@@ -1202,7 +1203,7 @@ ieee80211_crypto_aes_gmac_decrypt(struct ieee80211_rx_data *rx)
 		if (ieee80211_aes_gmac(key->u.aes_gmac.tfm, aad, nonce,
 				       skb->data + 24, skb->len - 24,
 				       mic) < 0 ||
-		    memcmp(mic, mmie->mic, sizeof(mmie->mic)) != 0) {
+		    crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
 			key->u.aes_gmac.icverrors++;
 			return RX_DROP_UNUSABLE;
 		}
-- 
2.13.1

WARNING: multiple messages have this Message-ID (diff)
From: "Jason A. Donenfeld" <Jason@zx2c4.com>
To: linux-kernel@vger.kernel.org, kernel-hardening@lists.openwall.com
Cc: "Jason A. Donenfeld" <Jason@zx2c4.com>,
	Johannes Berg <johannes@sipsolutions.net>,
	linux-wireless@vger.kernel.org, stable@vger.kernel.org
Subject: [PATCH 6/6] mac80211/wpa: use constant time memory comparison for MACs
Date: Sat, 10 Jun 2017 04:59:12 +0200	[thread overview]
Message-ID: <20170610025912.6499-7-Jason@zx2c4.com> (raw)
In-Reply-To: <20170610025912.6499-1-Jason@zx2c4.com>

Otherwise, we enable all sorts of forgeries via timing attack.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Cc: Johannes Berg <johannes@sipsolutions.net>
Cc: linux-wireless@vger.kernel.org
Cc: stable@vger.kernel.org
---
 net/mac80211/wpa.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/net/mac80211/wpa.c b/net/mac80211/wpa.c
index c1ef22df865f..cc19614ff4e6 100644
--- a/net/mac80211/wpa.c
+++ b/net/mac80211/wpa.c
@@ -17,6 +17,7 @@
 #include <asm/unaligned.h>
 #include <net/mac80211.h>
 #include <crypto/aes.h>
+#include <crypto/algapi.h>
 
 #include "ieee80211_i.h"
 #include "michael.h"
@@ -153,7 +154,7 @@ ieee80211_rx_h_michael_mic_verify(struct ieee80211_rx_data *rx)
 	data_len = skb->len - hdrlen - MICHAEL_MIC_LEN;
 	key = &rx->key->conf.key[NL80211_TKIP_DATA_OFFSET_RX_MIC_KEY];
 	michael_mic(key, hdr, data, data_len, mic);
-	if (memcmp(mic, data + data_len, MICHAEL_MIC_LEN) != 0)
+	if (crypto_memneq(mic, data + data_len, MICHAEL_MIC_LEN))
 		goto mic_fail;
 
 	/* remove Michael MIC from payload */
@@ -1048,7 +1049,7 @@ ieee80211_crypto_aes_cmac_decrypt(struct ieee80211_rx_data *rx)
 		bip_aad(skb, aad);
 		ieee80211_aes_cmac(key->u.aes_cmac.tfm, aad,
 				   skb->data + 24, skb->len - 24, mic);
-		if (memcmp(mic, mmie->mic, sizeof(mmie->mic)) != 0) {
+		if (crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
 			key->u.aes_cmac.icverrors++;
 			return RX_DROP_UNUSABLE;
 		}
@@ -1098,7 +1099,7 @@ ieee80211_crypto_aes_cmac_256_decrypt(struct ieee80211_rx_data *rx)
 		bip_aad(skb, aad);
 		ieee80211_aes_cmac_256(key->u.aes_cmac.tfm, aad,
 				       skb->data + 24, skb->len - 24, mic);
-		if (memcmp(mic, mmie->mic, sizeof(mmie->mic)) != 0) {
+		if (crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
 			key->u.aes_cmac.icverrors++;
 			return RX_DROP_UNUSABLE;
 		}
@@ -1202,7 +1203,7 @@ ieee80211_crypto_aes_gmac_decrypt(struct ieee80211_rx_data *rx)
 		if (ieee80211_aes_gmac(key->u.aes_gmac.tfm, aad, nonce,
 				       skb->data + 24, skb->len - 24,
 				       mic) < 0 ||
-		    memcmp(mic, mmie->mic, sizeof(mmie->mic)) != 0) {
+		    crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
 			key->u.aes_gmac.icverrors++;
 			return RX_DROP_UNUSABLE;
 		}
-- 
2.13.1

  parent reply	other threads:[~2017-06-10  2:59 UTC|newest]

Thread overview: 71+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-06-10  2:59 [kernel-hardening] [PATCH 0/6] Constant Time Memory Comparisons Are Important Jason A. Donenfeld
2017-06-10  2:59 ` Jason A. Donenfeld
2017-06-10  2:59 ` Jason A. Donenfeld
2017-06-10  2:59 ` [kernel-hardening] [PATCH 1/6] sunrpc: use constant time memory comparison for mac Jason A. Donenfeld
2017-06-10  2:59   ` Jason A. Donenfeld
2017-06-10  2:59 ` [kernel-hardening] [PATCH 2/6] net/ipv6: " Jason A. Donenfeld
2017-06-10  2:59   ` Jason A. Donenfeld
2017-06-10  2:59 ` [kernel-hardening] [PATCH 3/6] ccree: use constant time memory comparison for macs and tags Jason A. Donenfeld
2017-06-10  2:59   ` Jason A. Donenfeld
2017-06-10  7:43   ` [kernel-hardening] " Gilad Ben-Yossef
2017-06-10  7:43     ` Gilad Ben-Yossef
2017-06-10 10:54     ` [kernel-hardening] " Jason A. Donenfeld
2017-06-10 10:54       ` Jason A. Donenfeld
2017-06-10 21:43       ` [kernel-hardening] " Henrique de Moraes Holschuh
2017-06-10 21:43         ` Henrique de Moraes Holschuh
2017-06-10  2:59 ` [kernel-hardening] [PATCH 4/6] security/keys: use constant time memory comparison for macs Jason A. Donenfeld
2017-06-10  2:59   ` Jason A. Donenfeld
2017-06-10  2:59   ` Jason A. Donenfeld
2017-06-14  8:47   ` [kernel-hardening] " James Morris
2017-06-14  8:47     ` James Morris
2017-06-10  2:59 ` [kernel-hardening] [PATCH 5/6] bluetooth/smp: use constant time memory comparison for secret values Jason A. Donenfeld
2017-06-10  2:59   ` Jason A. Donenfeld
2017-06-10 13:49   ` [kernel-hardening] " Marcel Holtmann
2017-06-10 13:49     ` Marcel Holtmann
2017-06-10  2:59 ` Jason A. Donenfeld [this message]
2017-06-10  2:59   ` [PATCH 6/6] mac80211/wpa: use constant time memory comparison for MACs Jason A. Donenfeld
2017-06-13  8:20   ` [kernel-hardening] " Johannes Berg
2017-06-13  8:20     ` Johannes Berg
2017-06-13 13:28     ` [kernel-hardening] " Jason A. Donenfeld
2017-06-13 13:28       ` Jason A. Donenfeld
2017-06-11  8:13 ` [kernel-hardening] Re: [PATCH 0/6] Constant Time Memory Comparisons Are Important Kalle Valo
2017-06-11  8:13   ` Kalle Valo
2017-06-11  8:13   ` Kalle Valo
2017-06-11  8:13   ` Kalle Valo
2017-06-11 13:36   ` [kernel-hardening] " Kees Cook
2017-06-11 13:36     ` Kees Cook
2017-06-11 13:36     ` Kees Cook
2017-06-11 13:36     ` Kees Cook
2017-06-11 20:48     ` [kernel-hardening] " Emmanuel Grumbach
2017-06-11 20:48       ` Emmanuel Grumbach
2017-06-11 20:48       ` Emmanuel Grumbach
2017-06-11 20:48       ` Emmanuel Grumbach
2017-06-11 21:30       ` [kernel-hardening] " Emil Lenngren
2017-06-11 21:30         ` Emil Lenngren
2017-06-11 21:30         ` Emil Lenngren
2017-06-11 21:30         ` Emil Lenngren
2017-06-12  5:03         ` [kernel-hardening] " Emmanuel Grumbach
2017-06-12  5:03           ` Emmanuel Grumbach
2017-06-12  5:03           ` Emmanuel Grumbach
2017-06-12  5:03           ` Emmanuel Grumbach
2017-06-12  7:33         ` [kernel-hardening] " Arend van Spriel
2017-06-12  7:33           ` Arend van Spriel
2017-06-12  7:33           ` Arend van Spriel
2017-06-12  7:33           ` Arend van Spriel
2017-06-12 13:46           ` [kernel-hardening] " Kalle Valo
2017-06-12 13:46             ` Kalle Valo
2017-06-12 13:46             ` Kalle Valo
2017-06-11 21:06 ` [kernel-hardening] " Stephan Müller
2017-06-11 21:06   ` Stephan Müller
2017-06-11 21:06   ` Stephan Müller
2017-06-11 21:06   ` Stephan Müller
2017-06-11 21:21   ` [kernel-hardening] " Jason A. Donenfeld
2017-06-11 21:21     ` Jason A. Donenfeld
2017-06-11 21:21     ` Jason A. Donenfeld
2017-06-11 21:21     ` Jason A. Donenfeld
2017-06-11 21:21     ` Jason A. Donenfeld
2017-06-11 21:20 ` [kernel-hardening] [PATCH] rsa-pkcs1pad: use constant time memory comparison for MACs Jason A. Donenfeld
2017-06-11 21:20   ` Jason A. Donenfeld
2017-06-20  3:38   ` [kernel-hardening] " Herbert Xu
2017-06-20  3:38     ` Herbert Xu
2017-06-20  3:38     ` Herbert Xu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170610025912.6499-7-Jason@zx2c4.com \
    --to=jason@zx2c4.com \
    --cc=johannes@sipsolutions.net \
    --cc=kernel-hardening@lists.openwall.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.