From: Sabrina Dubroca <sd@queasysnail.net>
To: "Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>
Cc: Steffen Klassert <steffen.klassert@secunet.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] xfrm: esp6: fix off-by-one IV counter causing AES-GCM nonce reuse
Date: Mon, 28 Sep 2026 18:19:44 +0200 [thread overview]
Message-ID: <arqToNCxIwi9CZ--@krikkit> (raw)
In-Reply-To: <20260925095105.446269-2-Jeremy.Jean@oss.cyber.gouv.fr>
The subject prefix should be "PATCH ipsec" for IPsec bugfixes.
2026-09-25, 09:51:06 +0000, Jérémy Jean wrote:
> An off-by-one error in esp6_xmit() advances the IV counter before
> encrypting each software-GSO segment. For N segments with sequence
> numbers X through X+N-1, the IV counters are therefore X+1 through X+N.
> The following non-GSO packet uses X+N for both its sequence number and
> IV counter, repeating the last segment's AES-GCM nonce under the same
> key.
I find this description very unclear. All I'm managing to understand
from this is "there's some situation where a packet isn't getting the
seqno it should". I don't know where the "+1" comes from since for GSO
the function does +N (xo->seq.low += skb_shinfo(skb)->gso_segs).
Anyway, one process nit and one question on the code:
> The repeated nonce allows first a passive attacker who knows partial
> plaintext from one packet to recover corresponding bytes from another
> one, and second, an active attacker to recover GCM authentication key
> to forge authentication tags without recovering the AES key.
>
> Fix this by saving the complete current sequence number in esp.seqno
> before advancing the shared GSO sequence state.
>
> Fixes: 3dca3f38cfb8 ("xfrm: Separate ESP handling from segmentation for GRO packets.")
And if there's a crypto leak, this should probably have a "Cc: stable"
tag.
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
> ---
> net/ipv6/esp6_offload.c | 3 +--
> 1 file changed, 1 insertion(+), 2 deletions(-)
>
> diff --git a/net/ipv6/esp6_offload.c b/net/ipv6/esp6_offload.c
> index 2289552..05d13cc 100644
> --- a/net/ipv6/esp6_offload.c
> +++ b/net/ipv6/esp6_offload.c
> @@ -346,6 +346,7 @@ static int esp6_xmit(struct xfrm_state *x, struct sk_buff *skb, netdev_features
> }
>
> seq = xo->seq.low;
> + esp.seqno = cpu_to_be64(seq + ((u64)xo->seq.hi << 32));
>
> esp.esph = ip_esp_hdr(skb);
> esp.esph->spi = x->id.spi;
> @@ -364,8 +365,6 @@ static int esp6_xmit(struct xfrm_state *x, struct sk_buff *skb, netdev_features
> if (xo->seq.low < seq)
> xo->seq.hi++;
>
> - esp.seqno = cpu_to_be64(xo->seq.low + ((u64)xo->seq.hi << 32));
But then esp.seqno can have an inconsistent view of xo->seq.hi
compared to what esp6_output_tail/esp_output_set_esn will see
(xo->seq.hi++ just above this)?
--
Sabrina
next prev parent reply other threads:[~2026-09-28 16:19 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 9:51 [PATCH] xfrm: esp6: fix off-by-one IV counter causing AES-GCM nonce reuse Jérémy Jean
2026-09-28 16:19 ` Sabrina Dubroca [this message]
2026-09-28 19:33 ` Jérémy Jean
2026-09-28 23:48 ` Sabrina Dubroca
2026-09-29 9:47 ` Jérémy Jean
2026-09-29 13:00 ` Sabrina Dubroca
2026-09-29 13:13 ` Jérémy Jean
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arqToNCxIwi9CZ--@krikkit \
--to=sd@queasysnail.net \
--cc=Jeremy.Jean@oss.cyber.gouv.fr \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=steffen.klassert@secunet.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.