From: "Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>
To: Steffen Klassert <steffen.klassert@secunet.com>,
Herbert Xu <herbert@gondor.apana.org.au>
Cc: "David S . Miller" <davem@davemloft.net>,
"Sabrina Dubroca" <sd@queasysnail.net>,
"Saeed Mahameed" <saeedm@nvidia.com>,
"Leon Romanovsky" <leon@kernel.org>,
"Tariq Toukan" <tariqt@nvidia.com>,
"Mark Bloch" <mbloch@nvidia.com>,
"Boris Pismenny" <borisp@nvidia.com>,
netdev@vger.kernel.org,
"Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>
Subject: [PATCH ipsec 0/7] xfrm: fix ESP IV generation and ESN authentication
Date: Wed, 30 Sep 2026 14:45:17 +0000 [thread overview]
Message-ID: <20260930144523.435271-2-Jeremy.Jean@oss.cyber.gouv.fr> (raw)
Hello,
This series fixes nonce reuse in AES-GCM and ESN authentication errors
in the IPv4 and IPv6 ESP offload paths:
* 1/7 and 2/7: Save the current sequence number before incrementing it,
so that GCM IV construction prevents nonce reuse,
* 3/7: Use the current sequence for software AAD and hardware offload,
* 4/7: Give each early GSO segment a private secpath,
* 5/7: Use the packet sequence directly for mlx5 IV generation,
* 6/7: Segment untrusted GSO packets before allocating sequence numbers,
* 7/7: Keep the sequence counter unchanged after full ESN overflow.
Note that triggering the bug fixed by 7/7 is impractical: it requires
processing about 2^64 packets under a single key. Yet, I still believe
it's cleaner to fix it.
On the crypto side, as a reminder, reusing a nonce under the same GCM
key is catastrophic for security: it exposes the XOR of the plaintexts
and can reveal GCM authentication key, which opens the possibilty for
an adversary to forge ciphertexts without recovering the AES key.
This series combines and extends these two individual reports:
* https://lore.kernel.org/all/20260925095105.446269-2-Jeremy.Jean@oss.cyber.gouv.fr/
* https://lore.kernel.org/all/20260925095128.446450-2-Jeremy.Jean@oss.cyber.gouv.fr/
Recent discussion with Sabrina Dubroca may also be of interest:
https://lore.kernel.org/all/c443bad568f4e03d05b848b1b245707d@oss.cyber.gouv.fr/T/#u
Regards,
Jérémy
---
Jérémy Jean (7):
xfrm: esp6: use the current sequence number for the IV
xfrm: esp4: use the current sequence number for the IV
xfrm: esp: use the current sequence number for AAD and offload
xfrm: prevent AES-GCM nonce reuse after early GSO
net/mlx5e: Use the packet sequence number for the IPsec IV
xfrm: segment untrusted GSO packets before sequence allocation
xfrm: leave the sequence counter unchanged on ESN overflow
.../mellanox/mlx5/core/en_accel/ipsec_rxtx.c | 12 +-----------
net/ipv4/esp4.c | 13 ++++---------
net/ipv4/esp4_offload.c | 7 +++++--
net/ipv6/esp6.c | 13 ++++---------
net/ipv6/esp6_offload.c | 7 +++++--
net/xfrm/xfrm_output.c | 14 ++++++++++++--
net/xfrm/xfrm_replay.c | 1 -
7 files changed, 31 insertions(+), 36 deletions(-)
base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
--
2.47.3
next reply other threads:[~2026-09-30 14:46 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 14:45 Jérémy Jean [this message]
2026-09-30 14:45 ` [PATCH ipsec 1/7] xfrm: esp6: use the current sequence number for the IV Jérémy Jean
2026-09-30 14:45 ` [PATCH ipsec 2/7] xfrm: esp4: " Jérémy Jean
2026-09-30 14:45 ` [PATCH ipsec 3/7] xfrm: esp: use the current sequence number for AAD and offload Jérémy Jean
2026-09-30 14:45 ` [PATCH ipsec 4/7] xfrm: prevent AES-GCM nonce reuse after early GSO Jérémy Jean
2026-10-01 13:31 ` Sabrina Dubroca
2026-10-01 21:07 ` Jérémy Jean
2026-09-30 14:45 ` [PATCH ipsec 5/7] net/mlx5e: Use the packet sequence number for the IPsec IV Jérémy Jean
2026-10-01 11:42 ` Sabrina Dubroca
2026-10-01 19:33 ` Jérémy Jean
2026-10-05 13:06 ` Tariq Toukan
2026-10-05 13:50 ` Jérémy Jean
2026-10-05 18:28 ` Jérémy Jean
2026-10-06 6:49 ` Tariq Toukan
2026-10-06 8:51 ` Jérémy Jean
2026-09-30 14:45 ` [PATCH ipsec 6/7] xfrm: segment untrusted GSO packets before sequence allocation Jérémy Jean
2026-09-30 14:45 ` [PATCH ipsec 7/7] xfrm: leave the sequence counter unchanged on ESN overflow Jérémy Jean
2026-10-01 11:24 ` Sabrina Dubroca
2026-10-01 11:37 ` Jérémy Jean
2026-10-01 11:45 ` Sabrina Dubroca
2026-10-01 11:48 ` Jérémy Jean
2026-09-30 14:48 ` [PATCH ipsec 0/7] xfrm: fix ESP IV generation and ESN authentication netdev-bot+sinfo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930144523.435271-2-Jeremy.Jean@oss.cyber.gouv.fr \
--to=jeremy.jean@oss.cyber.gouv.fr \
--cc=borisp@nvidia.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=leon@kernel.org \
--cc=mbloch@nvidia.com \
--cc=netdev@vger.kernel.org \
--cc=saeedm@nvidia.com \
--cc=sd@queasysnail.net \
--cc=steffen.klassert@secunet.com \
--cc=tariqt@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox