From patchwork Wed Oct 25 01:56:01 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Levin, Alexander \(Sasha Levin\)" X-Patchwork-Id: 117007 Delivered-To: patch@linaro.org Received: by 10.140.22.164 with SMTP id 33csp332443qgn; Tue, 24 Oct 2017 19:14:31 -0700 (PDT) X-Google-Smtp-Source: ABhQp+SDb1bADPL293SCYYzUYd3JcvrQvnX3eihu+D2aHDSLoJ/QiFcTdlRkfZz5nXhgddAesDZy X-Received: by 10.99.95.76 with SMTP id t73mr585799pgb.57.1508897671604; Tue, 24 Oct 2017 19:14:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1508897671; cv=none; d=google.com; s=arc-20160816; b=hA1WuUr8LpqamL+a/nnArj0rCm27xUneE29Q23RTBRvO7urmk1W2DcyYfcGcMYbV+k +1SqGtwkGPMU9eQcZCIZGthsHnq11BsSWKzIXrUomQyTXjSxOqk+GAapOSsVcDnHFhXT 7jiwsQ8MH9kt77z/IttcCkeYMZSlwH444bYFE4Rm5WC3haimNwJOr1ZPVRNzoZCqw/Xb EL924jZu7XicySQ1/3mEymdxn6r7QQKF52OHgllSmKRS8MNn+7XjJDJRxi6xyW1rmbwL 16SDJWf03Bezg+pPNxfGa3ULV9QAqPX7rjUubO7aEZO7lPLDLen9BzbdfnefJ24d+apM 15/g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:to:dkim-signature :dkim-signature:cc:from:dkim-signature:arc-authentication-results; bh=I2/ColT1m6pN5adw5VQA7KMdwu/mMX63+Z4i9HRFB/A=; b=uq1jna2kEah6ts4vmv+w74N/QtkOPE+qQW3EIsuImYruHDZrGwUBME7xA5OnBUn4HP utHopg618qETyt18fW8iLCfneATiBDL5Uy8eIcvts3ibEXFHTeUhcJv9pndRaldLzyU4 7Wpj5LTK+D8qOl0MMfnNoC6qxj8FEDQRDLo8E4wE6ryjaDn7yjZ3J35L/2m7Vjpd6Ow0 T3DTksgUwvr+PRUw/mcoR+u19G4Zd6tYmaghXhn2GTbdEpDXI/zCxodw9qEX3lybBKdA svwjPNzmylb4AT8Bm4Ki4e/+qe2ZlarmxmCdNSCD8giFNu8cV+5bCeW/vF8LWb9BYLAd 1ZUA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@verizon.com header.s=corp header.b=VP9a2VtY; dkim=fail header.i=@verizon.com header.s=corp header.b=n90T85ta; dkim=fail header.i=@verizon.com header.s=corp header.b=n90T85ta; spf=pass (google.com: best guess record for domain of stable-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=stable-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=NONE dis=NONE) header.from=verizon.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id q81si1127687pfi.503.2017.10.24.19.14.31; Tue, 24 Oct 2017 19:14:31 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of stable-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@verizon.com header.s=corp header.b=VP9a2VtY; dkim=fail header.i=@verizon.com header.s=corp header.b=n90T85ta; dkim=fail header.i=@verizon.com header.s=corp header.b=n90T85ta; spf=pass (google.com: best guess record for domain of stable-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=stable-owner@vger.kernel.org; dmarc=pass (p=QUARANTINE sp=NONE dis=NONE) header.from=verizon.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751987AbdJYCOa (ORCPT + 9 others); Tue, 24 Oct 2017 22:14:30 -0400 Received: from omzsmtpe03.verizonbusiness.com ([199.249.25.208]:16025 "EHLO omzsmtpe03.verizonbusiness.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932348AbdJYB4x (ORCPT ); Tue, 24 Oct 2017 21:56:53 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=verizon.com; i=@verizon.com; q=dns/txt; s=corp; t=1508896613; x=1540432613; h=from:cc:to:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=s+xKgcmjAdTVce/RlxKairRMXsZrwgjUYha70LdWhtI=; b=VP9a2VtYeZKuUNVsWD3x1i1liKdgsHDAfNIF61udjkxdWkSZD2UKL2Qu hNYrv2mxGyeI1HSx+AcJp+C8nbpqXC6QsLAzDmd/aFLd37XJ7/xA2Vttr VYXJZY7TNTAFn++RAe6dRRnN2LJ0aGBqG2rL7fUn3XF1+MXS09yJ9SxNL E=; Received: from unknown (HELO fldsmtpi02.verizon.com) ([166.68.71.144]) by omzsmtpe03.verizonbusiness.com with ESMTP; 25 Oct 2017 01:56:46 +0000 From: "Levin, Alexander (Sasha Levin)" Cc: Gilad Ben-Yossef , Steffen Klassert , "Levin, Alexander (Sasha Levin)" Received: from rogue-10-255-192-101.rogue.vzwcorp.com (HELO atlantis.verizonwireless.com) ([10.255.192.101]) by fldsmtpi02.verizon.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 25 Oct 2017 01:56:46 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=verizon.com; i=@verizon.com; q=dns/txt; s=corp; t=1508896606; x=1540432606; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=s+xKgcmjAdTVce/RlxKairRMXsZrwgjUYha70LdWhtI=; b=n90T85tah7ng79DMUF7Lo9Vsr8alm+O05BcDRH338AU9zEN/VwcFvSVG I9mRIeUtaq/AVJnztq5aV9Dxc33QJgIttIRkUkZGHwX7DnXHgG2RRnXhB CnargjzHvjeIKoUz4i/fuk7V+UxTBkfopjnVCf3KuG2O6EHZmR5IFiEEx M=; Received: from mariner.tdc.vzwcorp.com (HELO eris.verizonwireless.com) ([10.254.88.84]) by atlantis.verizonwireless.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 24 Oct 2017 21:56:46 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=verizon.com; i=@verizon.com; q=dns/txt; s=corp; t=1508896606; x=1540432606; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=s+xKgcmjAdTVce/RlxKairRMXsZrwgjUYha70LdWhtI=; b=n90T85tah7ng79DMUF7Lo9Vsr8alm+O05BcDRH338AU9zEN/VwcFvSVG I9mRIeUtaq/AVJnztq5aV9Dxc33QJgIttIRkUkZGHwX7DnXHgG2RRnXhB CnargjzHvjeIKoUz4i/fuk7V+UxTBkfopjnVCf3KuG2O6EHZmR5IFiEEx M=; X-Host: mariner.tdc.vzwcorp.com Received: from ohtwi1exh001.uswin.ad.vzwcorp.com ([10.144.218.43]) by eris.verizonwireless.com with ESMTP/TLS/AES128-SHA256; 25 Oct 2017 01:56:46 +0000 Received: from tbwexch06apd.uswin.ad.vzwcorp.com (153.114.162.30) by OHTWI1EXH001.uswin.ad.vzwcorp.com (10.144.218.43) with Microsoft SMTP Server (TLS) id 14.3.248.2; Tue, 24 Oct 2017 21:56:46 -0400 Received: from OMZP1LUMXCA17.uswin.ad.vzwcorp.com (144.8.22.195) by tbwexch06apd.uswin.ad.vzwcorp.com (153.114.162.30) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Tue, 24 Oct 2017 21:56:45 -0400 Received: from OMZP1LUMXCA17.uswin.ad.vzwcorp.com (144.8.22.195) by OMZP1LUMXCA17.uswin.ad.vzwcorp.com (144.8.22.195) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Tue, 24 Oct 2017 20:56:44 -0500 Received: from OMZP1LUMXCA17.uswin.ad.vzwcorp.com ([144.8.22.195]) by OMZP1LUMXCA17.uswin.ad.vzwcorp.com ([144.8.22.195]) with mapi id 15.00.1263.000; Tue, 24 Oct 2017 20:56:44 -0500 To: "linux-kernel@vger.kernel.org" , "stable@vger.kernel.org" Subject: [PATCH AUTOSEL for 4.9 36/50] IPsec: do not ignore crypto err in ah4 input Thread-Topic: [PATCH AUTOSEL for 4.9 36/50] IPsec: do not ignore crypto err in ah4 input Thread-Index: AQHTTTRohMno4A3g0USkqi3UpwWQAQ== Date: Wed, 25 Oct 2017 01:56:01 +0000 Message-ID: <20171025015539.24525-36-alexander.levin@verizon.com> References: <20171025015539.24525-1-alexander.levin@verizon.com> In-Reply-To: <20171025015539.24525-1-alexander.levin@verizon.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-exchange-messagesentrepresentingtype: 1 x-ms-exchange-transport-fromentityheader: Hosted x-originating-ip: [10.144.60.250] MIME-Version: 1.0 Sender: stable-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: stable@vger.kernel.org From: Gilad Ben-Yossef [ Upstream commit ebd89a2d0675f1325c2be5b7576fd8cb7e8defd0 ] ah4 input processing uses the asynchronous hash crypto API which supplies an error code as part of the operation completion but the error code was being ignored. Treat a crypto API error indication as a verification failure. While a crypto API reported error would almost certainly result in a memcpy of the digest failing anyway and thus the security risk seems minor, performing a memory compare on what might be uninitialized memory is wrong. Signed-off-by: Gilad Ben-Yossef Signed-off-by: Steffen Klassert Signed-off-by: Sasha Levin --- net/ipv4/ah4.c | 3 +++ 1 file changed, 3 insertions(+) -- 2.11.0 diff --git a/net/ipv4/ah4.c b/net/ipv4/ah4.c index f2a71025a770..22377c8ff14b 100644 --- a/net/ipv4/ah4.c +++ b/net/ipv4/ah4.c @@ -270,6 +270,9 @@ static void ah_input_done(struct crypto_async_request *base, int err) int ihl = ip_hdrlen(skb); int ah_hlen = (ah->hdrlen + 2) << 2; + if (err) + goto out; + work_iph = AH_SKB_CB(skb)->tmp; auth_data = ah_tmp_auth(work_iph, ihl); icv = ah_tmp_icv(ahp->ahash, auth_data, ahp->icv_trunc_len);