From: "Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>
To: Sabrina Dubroca <sd@queasysnail.net>
Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
"Jérémy Jean" <Jeremy.Jean@oss.cyber.gouv.fr>,
stable@vger.kernel.org
Subject: [PATCH net] macsec: prevent AES-GCM nonce reuse after packet number wrap
Date: Wed, 30 Sep 2026 20:33:33 +0000 [thread overview]
Message-ID: <20260930203333.598733-2-Jeremy.Jean@oss.cyber.gouv.fr> (raw)
When MACsec uses 32-bit packet numbers, 0xffffffff is the last valid
packet number, and after allocating it, MACsec deactivates the
transmit SA and wraps the next packet number to zero. Packets already
in flight can still be processed after that.
The first late packet gets packet number zero and is dropped, but
tx_sa_update_pn() has already advanced the stored counter to one before
macsec_encrypt() drops it. A second late packet can then be sent with
packet number one again, reusing the AES-GCM nonce from the start of the
SA.
Keep next_pn at zero after wrap so all late packets are dropped.
Fixes: c09440f7dcb3 ("macsec: introduce IEEE 802.1AE driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
---
drivers/net/macsec.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/net/macsec.c b/drivers/net/macsec.c
index 78a19b134632..233391acebb0 100644
--- a/drivers/net/macsec.c
+++ b/drivers/net/macsec.c
@@ -486,6 +486,9 @@ static pn_t tx_sa_update_pn(struct macsec_tx_sa *tx_sa,
spin_lock_bh(&tx_sa->lock);
pn = tx_sa->next_pn_halves;
+ if (unlikely(pn.full64 == 0))
+ goto out;
+
if (secy->xpn)
tx_sa->next_pn++;
else
@@ -493,6 +496,8 @@ static pn_t tx_sa_update_pn(struct macsec_tx_sa *tx_sa,
if (tx_sa->next_pn == 0)
__macsec_pn_wrapped(secy, tx_sa);
+
+out:
spin_unlock_bh(&tx_sa->lock);
return pn;
--
2.47.3
next reply other threads:[~2026-09-30 20:36 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 20:33 Jérémy Jean [this message]
2026-09-30 20:38 ` [PATCH net] macsec: prevent AES-GCM nonce reuse after packet number wrap netdev-bot+sinfo
2026-10-01 9:43 ` Sabrina Dubroca
2026-10-01 15:08 ` Jérémy Jean
2026-10-02 11:35 ` netdev-bot+sashiko
2026-10-02 15:22 ` Jérémy Jean
2026-10-08 0:07 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930203333.598733-2-Jeremy.Jean@oss.cyber.gouv.fr \
--to=jeremy.jean@oss.cyber.gouv.fr \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=sd@queasysnail.net \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox