From nobody Sat Jul 25 15:25:25 2026 Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 76BA334AB19 for ; Thu, 16 Jul 2026 19:31:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784230272; cv=none; b=J5j0cTDTbUt1alM/TJMz7dwhNWizEz3kvQ65V1hqC+JMiNvG5klVdaTzJscHZUhTkLMZxqmyUs+Wy1fYPLwTZWRVAlqnbK6lYuiThiE0WZk9WR2w+WYBPd7gvpK5VfOO9ifmywdo2pA31sG7aEwveKIm7X+aZtO8uVRbtikbL0A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784230272; c=relaxed/simple; bh=6pGsiGHzTol19T8ksztlrGoKHMwqFsepeExiisUiMDQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JTJdJB0SzIEIB4FDFEuzyXKOubhtmROMjCGDQAXoH53+51lFtrk4alHtMZxSAPOsjgz94q3/9Ynsn9K/VZg0XEo+tl/DVxzBsrREVjekGB/RsARLTqkf5fgu1SoHEa/QDrYmW/h37vLUwrOa7iXEm3Vu6lI3uDfQmsmIZYtB92M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=aBS/6RES; arc=none smtp.client-ip=209.85.221.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="aBS/6RES" Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-4629051c9d1so2251765f8f.2 for ; Thu, 16 Jul 2026 12:31:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1784230269; x=1784835069; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=34nlX8hiehezECUHqMooipflNwUN2ehZF7eJFTVK0nA=; b=aBS/6RESfLbfQ4UQWQ/0Z+ELAgUhKt5jMCpMOtaWFOkQEdIVgH7THy/MkW6YKjGgTZ P7fwBrJ/DSwlXbNVo7H+AY5Y51mCiwVt3ExKg2/Jq4KSekbH4w5WBwSPBdr9QwG9o0Fr gzKDTtAK56l1fU+XXPQY3viAMa+dcPaNPhBwS1CIvddcPlwc5rXUwKpc0cNaBhLI1AfR F9dMGVKFHh+wysutys2FW/hVDQ8gbyJkuw7FPP6omBT5PuySflofoSj7TEB5HejRjcDG pOVhas2sVQ5zAlabr3Vt0B26BxV02u3rpkYix91CRp5Y9f9bFwagOuj7nwvD8PJYZvep zbkg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784230269; x=1784835069; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=34nlX8hiehezECUHqMooipflNwUN2ehZF7eJFTVK0nA=; b=cz/4/ymIZblMb6K0Sd00flfWW2hPM0dXfGJFwGzZAcvLXcuBagFIMuinrq0rI/foeN gJjmDHryLrY56nQXqMZXdUpigDN78QyEeG54Beg4jx4hZVpppfEyy13H3vFUcQHyjDE0 0Ug93hYEqagOS/rjeS19naJUdHvsPGB91NyPZXDKypQ0n6pHqRbThDl7YKk+KidzE1Zc YaqZurgkrSl+OHUL9H+D6FezM3jL9YdU33rjJGlATT/LiQWyQ7o8AiY/AxhKSGPIOy7p cq1HLfYa/GTUW6YhHzJx4ONTPvoFLEoi8BREtsm14/V2qjndLRZAFf1ruknz+C3CodM2 23cg== X-Forwarded-Encrypted: i=1; AHgh+RplJIGlwB3uOINCSzwtBOPDza8jhQdDzXWwafEBBQhf7H6fAKYMR7EX4EMcycxUSV0CQ5fasJinVW/hfMA=@vger.kernel.org X-Gm-Message-State: AOJu0YzeRMV2hrUDJw1v7MlMRJ9aopKKwFmkciZAva0DteSL1g3GpGJj owEE+V3INQcq0Mr7gJedcVa8Vnt+DSMGOB5W6xJ7jVgpa0AV/Pq4XFY71SMfhWQNpFPT X-Gm-Gg: AfdE7cmRvsOSM3eGsJ3d01PT1uDs8xcOCQdUdi2UmmupeLq7Ff6dhzbnP12oeDhse8j x7vfH4N/sjf6miz4XHnzxrvbA7V2+qV+3s6Yz3hI+Ifp1GIki9nvietRrX4OZZ9TnwJRrxaWnnh 8HKo7bV+IjHQp2TSOsOJOSoArGWuMl2u6TrdXdWpBuZms6SSoRZEjiBmIr8ZfScNRELT3zeStlO FBamku5i1VTKkZVqgV10cTrrmRsjlkRuIbBhfBup4jm2FXB+AkgFDXJS1WfS22fre7X7nJ8xoKY CJvTA7vA5Xac6QR/lo06ODbufRr/GcKL4L0U8vVrfJnBgvn5wo7+0epG8JRV9Cb8wQttLf/3V9V 6iYsXmlDMul+5+ESVTc6PcL/IDJRT4VF0ONosZwz15ByQjbrug0THz+hi790cgxomCF1lJPUOD5 2zTaHPYwCcv3zzWd7hfZsHVEA7QN47UJTHK7cTS+ghC2bxKQVQBT0XgruVWbIQUA7IhtDfAuK0s AmaYfXkD79bi42ydLto3p4U X-Received: by 2002:a05:6000:4710:b0:45e:73eb:5119 with SMTP id ffacd0b85a97d-47f608884f7mr449931f8f.22.1784230268556; Thu, 16 Jul 2026 12:31:08 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f464caeffsm24920545f8f.36.2026.07.16.12.31.07 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 16 Jul 2026 12:31:08 -0700 (PDT) From: Doruk Tan Ozturk To: alex.aring@gmail.com, stefan@datenfreihafen.org, miquel.raynal@bootlin.com Cc: davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com, horms@kernel.org, leitao@debian.org, linux-wpan@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net v2] mac802154: llsec: reject frames shorter than the authentication tag Date: Thu, 16 Jul 2026 21:31:06 +0200 Message-ID: <20260716193106.30607-1-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260709131246.44517-1-doruk@0sec.ai> References: <20260709131246.44517-1-doruk@0sec.ai> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" llsec_do_decrypt_auth() computes the associated-data length for the AEAD request as assoclen +=3D datalen - authlen; where datalen is the number of bytes after the MAC header and authlen (4, 8 or 16) is the length of the authentication tag. Nothing verifies that the frame actually carries at least authlen payload bytes. A secured frame whose payload is shorter than the tag makes datalen - authlen negative; assoclen is then passed to aead_request_set_ad() as an unsigned value close to 4 GiB, so crypto_aead_decrypt() walks far off the end of the scatterlist that only spans the real frame. The frame is fully attacker-controlled and reaches this path from any IEEE 802.15.4 peer in radio range. Reject frames whose payload is shorter than the authentication tag before the subtraction. Dynamically reproduced on a KASAN kernel as a general-protection-fault in the AEAD scatterwalk, and the fix confirmed. Fixes: 4c14a2fb5d14 ("mac802154: add llsec decryption method") Cc: stable@vger.kernel.org Assisted-by: 0sec:multi-model Reviewed-by: Simon Horman Signed-off-by: Doruk Tan Ozturk --- v2 (Breno Leitao review): - drop the redundant self-Reported-by. - move the length check above sg_init_one() (datalen/authlen are already available there). - Assisted-by trailer -> 0sec:multi-model. Carrying Simon Horman Reviewed-by; v2 only moves the same check earlier. net/mac802154/llsec.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/net/mac802154/llsec.c b/net/mac802154/llsec.c index 5e7cc11fab3a..85452ef9a58c 100644 --- a/net/mac802154/llsec.c +++ b/net/mac802154/llsec.c @@ -891,6 +891,11 @@ llsec_do_decrypt_auth(struct sk_buff *skb, const struc= t mac802154_llsec *sec, data =3D skb_mac_header(skb) + skb->mac_len; datalen =3D skb_tail_pointer(skb) - data; =20 + if (datalen < authlen) { + kfree_sensitive(req); + return -EBADMSG; + } + sg_init_one(&sg, skb_mac_header(skb), assoclen + datalen); =20 if (!(hdr->sec.level & IEEE802154_SCF_SECLEVEL_ENC)) { --=20 2.43.0