* [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag
2026-07-09 13:12 [PATCH net] " Doruk Tan Ozturk
@ 2026-07-16 19:31 ` Doruk Tan Ozturk
2026-07-17 8:05 ` Breno Leitao
0 siblings, 1 reply; 4+ messages in thread
From: Doruk Tan Ozturk @ 2026-07-16 19:31 UTC (permalink / raw)
To: alex.aring, stefan, miquel.raynal
Cc: davem, edumazet, kuba, pabeni, horms, leitao, linux-wpan, netdev,
linux-kernel, stable
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen - authlen;
where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.
The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.
Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed.
Fixes: 4c14a2fb5d14 ("mac802154: add llsec decryption method")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:multi-model
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
---
v2 (Breno Leitao review):
- drop the redundant self-Reported-by.
- move the length check above sg_init_one() (datalen/authlen are
already available there).
- Assisted-by trailer -> 0sec:multi-model.
Carrying Simon Horman Reviewed-by; v2 only moves the same check earlier.
net/mac802154/llsec.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/mac802154/llsec.c b/net/mac802154/llsec.c
index 5e7cc11fab3a..85452ef9a58c 100644
--- a/net/mac802154/llsec.c
+++ b/net/mac802154/llsec.c
@@ -891,6 +891,11 @@ llsec_do_decrypt_auth(struct sk_buff *skb, const struct mac802154_llsec *sec,
data = skb_mac_header(skb) + skb->mac_len;
datalen = skb_tail_pointer(skb) - data;
+ if (datalen < authlen) {
+ kfree_sensitive(req);
+ return -EBADMSG;
+ }
+
sg_init_one(&sg, skb_mac_header(skb), assoclen + datalen);
if (!(hdr->sec.level & IEEE802154_SCF_SECLEVEL_ENC)) {
--
2.43.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag
@ 2026-07-16 19:34 Doruk Tan Ozturk
2026-07-23 15:20 ` patchwork-bot+netdevbpf
0 siblings, 1 reply; 4+ messages in thread
From: Doruk Tan Ozturk @ 2026-07-16 19:34 UTC (permalink / raw)
To: alex.aring, stefan, miquel.raynal
Cc: davem, edumazet, kuba, pabeni, horms, leitao, linux-wpan, netdev,
linux-kernel, stable
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen - authlen;
where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.
The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.
Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed.
Fixes: 4c14a2fb5d14 ("mac802154: add llsec decryption method")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:multi-model
Reviewed-by: Simon Horman <horms@kernel.org>
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
---
v2 (Breno Leitao review):
- drop the redundant self-Reported-by.
- move the length check above sg_init_one() (datalen/authlen are
already available there).
- Assisted-by trailer -> 0sec:multi-model.
Carrying Simon Horman Reviewed-by; v2 only moves the same check earlier.
net/mac802154/llsec.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/mac802154/llsec.c b/net/mac802154/llsec.c
index 5e7cc11fab3a..85452ef9a58c 100644
--- a/net/mac802154/llsec.c
+++ b/net/mac802154/llsec.c
@@ -891,6 +891,11 @@ llsec_do_decrypt_auth(struct sk_buff *skb, const struct mac802154_llsec *sec,
data = skb_mac_header(skb) + skb->mac_len;
datalen = skb_tail_pointer(skb) - data;
+ if (datalen < authlen) {
+ kfree_sensitive(req);
+ return -EBADMSG;
+ }
+
sg_init_one(&sg, skb_mac_header(skb), assoclen + datalen);
if (!(hdr->sec.level & IEEE802154_SCF_SECLEVEL_ENC)) {
--
2.43.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag
2026-07-16 19:31 ` [PATCH net v2] " Doruk Tan Ozturk
@ 2026-07-17 8:05 ` Breno Leitao
0 siblings, 0 replies; 4+ messages in thread
From: Breno Leitao @ 2026-07-17 8:05 UTC (permalink / raw)
To: Doruk Tan Ozturk
Cc: alex.aring, stefan, miquel.raynal, davem, edumazet, kuba, pabeni,
horms, linux-wpan, netdev, linux-kernel, stable
On Thu, Jul 16, 2026 at 09:31:06PM +0200, Doruk Tan Ozturk wrote:
> llsec_do_decrypt_auth() computes the associated-data length for the
> AEAD request as
>
> assoclen += datalen - authlen;
>
> where datalen is the number of bytes after the MAC header and authlen
> (4, 8 or 16) is the length of the authentication tag. Nothing verifies
> that the frame actually carries at least authlen payload bytes. A
> secured frame whose payload is shorter than the tag makes
> datalen - authlen negative; assoclen is then passed to
> aead_request_set_ad() as an unsigned value close to 4 GiB, so
> crypto_aead_decrypt() walks far off the end of the scatterlist that
> only spans the real frame.
>
> The frame is fully attacker-controlled and reaches this path from any
> IEEE 802.15.4 peer in radio range. Reject frames whose payload is
> shorter than the authentication tag before the subtraction.
>
> Dynamically reproduced on a KASAN kernel as a general-protection-fault
> in the AEAD scatterwalk, and the fix confirmed.
>
> Fixes: 4c14a2fb5d14 ("mac802154: add llsec decryption method")
> Cc: stable@vger.kernel.org
> Assisted-by: 0sec:multi-model
> Reviewed-by: Simon Horman <horms@kernel.org>
> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Reviwed-by: Breno Leitao <leitao@debian.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag
2026-07-16 19:34 [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag Doruk Tan Ozturk
@ 2026-07-23 15:20 ` patchwork-bot+netdevbpf
0 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-07-23 15:20 UTC (permalink / raw)
To: Doruk Tan Ozturk
Cc: alex.aring, stefan, miquel.raynal, davem, edumazet, kuba, pabeni,
horms, leitao, linux-wpan, netdev, linux-kernel, stable
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Thu, 16 Jul 2026 21:34:23 +0200 you wrote:
> llsec_do_decrypt_auth() computes the associated-data length for the
> AEAD request as
>
> assoclen += datalen - authlen;
>
> where datalen is the number of bytes after the MAC header and authlen
> (4, 8 or 16) is the length of the authentication tag. Nothing verifies
> that the frame actually carries at least authlen payload bytes. A
> secured frame whose payload is shorter than the tag makes
> datalen - authlen negative; assoclen is then passed to
> aead_request_set_ad() as an unsigned value close to 4 GiB, so
> crypto_aead_decrypt() walks far off the end of the scatterlist that
> only spans the real frame.
>
> [...]
Here is the summary with links:
- [net,v2] mac802154: llsec: reject frames shorter than the authentication tag
https://git.kernel.org/netdev/net/c/fd3a3f28ed60
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-07-23 15:20 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-16 19:34 [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag Doruk Tan Ozturk
2026-07-23 15:20 ` patchwork-bot+netdevbpf
-- strict thread matches above, loose matches on Subject: below --
2026-07-09 13:12 [PATCH net] " Doruk Tan Ozturk
2026-07-16 19:31 ` [PATCH net v2] " Doruk Tan Ozturk
2026-07-17 8:05 ` Breno Leitao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox