* [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time
@ 2026-03-02 20:36 Eric Biggers
2026-03-02 20:59 ` Dmitry Safonov
2026-03-04 1:30 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 4+ messages in thread
From: Eric Biggers @ 2026-03-02 20:36 UTC (permalink / raw)
To: netdev, David S . Miller, David Ahern, Eric Dumazet,
Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Neal Cardwell, Kuniyuki Iwashima, linux-crypto,
linux-kernel, Eric Biggers, stable, Dmitry Safonov
To prevent timing attacks, MACs need to be compared in constant
time. Use the appropriate helper function for this.
Fixes: 0a3a809089eb ("net/tcp: Verify inbound TCP-AO signed segments")
Cc: stable@vger.kernel.org
Cc: Dmitry Safonov <0x7f454c46@gmail.com>
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
---
net/ipv4/Kconfig | 1 +
net/ipv4/tcp_ao.c | 3 ++-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/net/ipv4/Kconfig b/net/ipv4/Kconfig
index b71c22475c515..3ab6247be5853 100644
--- a/net/ipv4/Kconfig
+++ b/net/ipv4/Kconfig
@@ -746,10 +746,11 @@ config TCP_SIGPOOL
tristate
config TCP_AO
bool "TCP: Authentication Option (RFC5925)"
select CRYPTO
+ select CRYPTO_LIB_UTILS
select TCP_SIGPOOL
depends on 64BIT && IPV6 != m # seq-number extension needs WRITE_ONCE(u64)
help
TCP-AO specifies the use of stronger Message Authentication Codes (MACs),
protects against replays for long-lived TCP connections, and
diff --git a/net/ipv4/tcp_ao.c b/net/ipv4/tcp_ao.c
index 4980caddb0fc4..a97cdf3e6af4c 100644
--- a/net/ipv4/tcp_ao.c
+++ b/net/ipv4/tcp_ao.c
@@ -8,10 +8,11 @@
* Salam Noureddine <noureddine@arista.com>
*/
#define pr_fmt(fmt) "TCP: " fmt
#include <crypto/hash.h>
+#include <crypto/utils.h>
#include <linux/inetdevice.h>
#include <linux/tcp.h>
#include <net/tcp.h>
#include <net/ipv6.h>
@@ -920,11 +921,11 @@ tcp_ao_verify_hash(const struct sock *sk, const struct sk_buff *skb,
return SKB_DROP_REASON_NOT_SPECIFIED;
/* XXX: make it per-AF callback? */
tcp_ao_hash_skb(family, hash_buf, key, sk, skb, traffic_key,
(phash - (u8 *)th), sne);
- if (memcmp(phash, hash_buf, maclen)) {
+ if (crypto_memneq(phash, hash_buf, maclen)) {
NET_INC_STATS(sock_net(sk), LINUX_MIB_TCPAOBAD);
atomic64_inc(&info->counters.pkt_bad);
atomic64_inc(&key->pkt_bad);
trace_tcp_ao_mismatch(sk, skb, aoh->keyid,
aoh->rnext_keyid, maclen);
base-commit: 9439a661c2e80485406ce2c90b107ca17858382d
--
2.53.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time
2026-03-02 20:36 [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time Eric Biggers
@ 2026-03-02 20:59 ` Dmitry Safonov
2026-03-02 21:24 ` Eric Biggers
2026-03-04 1:30 ` patchwork-bot+netdevbpf
1 sibling, 1 reply; 4+ messages in thread
From: Dmitry Safonov @ 2026-03-02 20:59 UTC (permalink / raw)
To: Eric Biggers
Cc: netdev, David S . Miller, David Ahern, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Simon Horman, Neal Cardwell,
Kuniyuki Iwashima, linux-crypto, linux-kernel, stable
On Mon, 2 Mar 2026 at 20:36, Eric Biggers <ebiggers@kernel.org> wrote:
>
> To prevent timing attacks, MACs need to be compared in constant
> time. Use the appropriate helper function for this.
>
> Fixes: 0a3a809089eb ("net/tcp: Verify inbound TCP-AO signed segments")
> Cc: stable@vger.kernel.org
> Cc: Dmitry Safonov <0x7f454c46@gmail.com>
> Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Thanks, Eric, LGTM.
Reviewed-by: Dmitry Safonov <0x7f454c46@gmail.com>
Could you also send a similar patch for TCP-MD5?
tcp_inbound_md5_hash(), tcp_v{4,6}_send_reset() would need the same change.
> ---
> net/ipv4/Kconfig | 1 +
> net/ipv4/tcp_ao.c | 3 ++-
> 2 files changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/net/ipv4/Kconfig b/net/ipv4/Kconfig
> index b71c22475c515..3ab6247be5853 100644
> --- a/net/ipv4/Kconfig
> +++ b/net/ipv4/Kconfig
> @@ -746,10 +746,11 @@ config TCP_SIGPOOL
> tristate
>
> config TCP_AO
> bool "TCP: Authentication Option (RFC5925)"
> select CRYPTO
> + select CRYPTO_LIB_UTILS
> select TCP_SIGPOOL
> depends on 64BIT && IPV6 != m # seq-number extension needs WRITE_ONCE(u64)
> help
> TCP-AO specifies the use of stronger Message Authentication Codes (MACs),
> protects against replays for long-lived TCP connections, and
> diff --git a/net/ipv4/tcp_ao.c b/net/ipv4/tcp_ao.c
> index 4980caddb0fc4..a97cdf3e6af4c 100644
> --- a/net/ipv4/tcp_ao.c
> +++ b/net/ipv4/tcp_ao.c
> @@ -8,10 +8,11 @@
> * Salam Noureddine <noureddine@arista.com>
> */
> #define pr_fmt(fmt) "TCP: " fmt
>
> #include <crypto/hash.h>
> +#include <crypto/utils.h>
> #include <linux/inetdevice.h>
> #include <linux/tcp.h>
>
> #include <net/tcp.h>
> #include <net/ipv6.h>
> @@ -920,11 +921,11 @@ tcp_ao_verify_hash(const struct sock *sk, const struct sk_buff *skb,
> return SKB_DROP_REASON_NOT_SPECIFIED;
>
> /* XXX: make it per-AF callback? */
> tcp_ao_hash_skb(family, hash_buf, key, sk, skb, traffic_key,
> (phash - (u8 *)th), sne);
> - if (memcmp(phash, hash_buf, maclen)) {
> + if (crypto_memneq(phash, hash_buf, maclen)) {
> NET_INC_STATS(sock_net(sk), LINUX_MIB_TCPAOBAD);
> atomic64_inc(&info->counters.pkt_bad);
> atomic64_inc(&key->pkt_bad);
> trace_tcp_ao_mismatch(sk, skb, aoh->keyid,
> aoh->rnext_keyid, maclen);
>
> base-commit: 9439a661c2e80485406ce2c90b107ca17858382d
> --
> 2.53.0
>
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time
2026-03-02 20:59 ` Dmitry Safonov
@ 2026-03-02 21:24 ` Eric Biggers
0 siblings, 0 replies; 4+ messages in thread
From: Eric Biggers @ 2026-03-02 21:24 UTC (permalink / raw)
To: Dmitry Safonov
Cc: netdev, David S . Miller, David Ahern, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, Simon Horman, Neal Cardwell,
Kuniyuki Iwashima, linux-crypto, linux-kernel, stable
On Mon, Mar 02, 2026 at 08:59:50PM +0000, Dmitry Safonov wrote:
> On Mon, 2 Mar 2026 at 20:36, Eric Biggers <ebiggers@kernel.org> wrote:
> >
> > To prevent timing attacks, MACs need to be compared in constant
> > time. Use the appropriate helper function for this.
> >
> > Fixes: 0a3a809089eb ("net/tcp: Verify inbound TCP-AO signed segments")
> > Cc: stable@vger.kernel.org
> > Cc: Dmitry Safonov <0x7f454c46@gmail.com>
> > Signed-off-by: Eric Biggers <ebiggers@kernel.org>
>
> Thanks, Eric, LGTM.
>
> Reviewed-by: Dmitry Safonov <0x7f454c46@gmail.com>
>
> Could you also send a similar patch for TCP-MD5?
> tcp_inbound_md5_hash(), tcp_v{4,6}_send_reset() would need the same change.
Already done, it was the first one I sent:
https://lore.kernel.org/netdev/20260302203409.13388-1-ebiggers@kernel.org/
- Eric
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time
2026-03-02 20:36 [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time Eric Biggers
2026-03-02 20:59 ` Dmitry Safonov
@ 2026-03-04 1:30 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-03-04 1:30 UTC (permalink / raw)
To: Eric Biggers
Cc: netdev, davem, dsahern, edumazet, kuba, pabeni, horms, ncardwell,
kuniyu, linux-crypto, linux-kernel, stable, 0x7f454c46
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Mon, 2 Mar 2026 12:36:00 -0800 you wrote:
> To prevent timing attacks, MACs need to be compared in constant
> time. Use the appropriate helper function for this.
>
> Fixes: 0a3a809089eb ("net/tcp: Verify inbound TCP-AO signed segments")
> Cc: stable@vger.kernel.org
> Cc: Dmitry Safonov <0x7f454c46@gmail.com>
> Signed-off-by: Eric Biggers <ebiggers@kernel.org>
>
> [...]
Here is the summary with links:
- [net] net/tcp-ao: Fix MAC comparison to be constant-time
https://git.kernel.org/netdev/net/c/67edfec516d3
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-03-04 1:30 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-03-02 20:36 [PATCH net] net/tcp-ao: Fix MAC comparison to be constant-time Eric Biggers
2026-03-02 20:59 ` Dmitry Safonov
2026-03-02 21:24 ` Eric Biggers
2026-03-04 1:30 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox