]> git.hungrycats.org Git - linux/commitdiff
xfrm: fix xfrm_state_construct() auth-trunc leak
authorZihan Xi <zihanx@nebusec.ai>
Mon, 27 Jul 2026 17:30:32 +0000 (01:30 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 2 Sep 2026 12:31:49 +0000 (14:31 +0200)
commit c12cbf56320fb633484ee0ca1fb7d68d6b64b213 upstream.

attach_auth_trunc() can allocate x->aalg while leaving
x->props.aalgo at zero when the selected auth algorithm has no
sadb_alg_id. One real case is cmac(aes).

xfrm_state_construct() then treats !x->props.aalgo as "no auth
algorithm attached yet" and calls attach_auth(). That overwrites
x->aalg and loses the first allocation. Any later failure or teardown
only frees the replacement pointer.

Check whether x->aalg is already attached instead of inferring that
state from x->props.aalgo.

Fixes: 4447bb33f094 ("xfrm: Store aalg in xfrm_state with a user specified truncation length")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: Codex:gpt-5.4
Signed-off-by: Zihan Xi <zihanx@nebusec.ai>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/xfrm/xfrm_user.c

index 3641ccccbc4153218c9cb69e0b4504aa816af836..0f0384b6a11d09b0dbf2f10900a441b1dd6334b1 100644 (file)
@@ -916,7 +916,7 @@ static struct xfrm_state *xfrm_state_construct(struct net *net,
        if ((err = attach_auth_trunc(&x->aalg, &x->props.aalgo,
                                     attrs[XFRMA_ALG_AUTH_TRUNC], extack)))
                goto error;
-       if (!x->props.aalgo) {
+       if (!x->aalg) {
                if ((err = attach_auth(&x->aalg, &x->props.aalgo,
                                       attrs[XFRMA_ALG_AUTH], extack)))
                        goto error;