summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorZihan Xi <zihanx@nebusec.ai>2026-07-28 01:30:32 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-09-02 14:29:20 +0200
commitc8837bbe792257af547fd1c0252553ce13148795 (patch)
tree6b9abc219ae48fc6705bf9f2e57c9c7d8b34b2ec
parentf00df8500e5a36ba70d336fd34bd2152ea074e5f (diff)
downloadlinux-stable-c8837bbe792257af547fd1c0252553ce13148795.tar.gz
linux-stable-c8837bbe792257af547fd1c0252553ce13148795.zip
xfrm: fix xfrm_state_construct() auth-trunc leak
commit c12cbf56320fb633484ee0ca1fb7d68d6b64b213 upstream. attach_auth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when the selected auth algorithm has no sadb_alg_id. One real case is cmac(aes). xfrm_state_construct() then treats !x->props.aalgo as "no auth algorithm attached yet" and calls attach_auth(). That overwrites x->aalg and loses the first allocation. Any later failure or teardown only frees the replacement pointer. Check whether x->aalg is already attached instead of inferring that state from x->props.aalgo. Fixes: 4447bb33f094 ("xfrm: Store aalg in xfrm_state with a user specified truncation length") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Assisted-by: Codex:gpt-5.4 Signed-off-by: Zihan Xi <zihanx@nebusec.ai> Signed-off-by: Ren Wei <enjou1224z@gmail.com> Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--net/xfrm/xfrm_user.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index cd6898833ce0..419af08e31a2 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -716,7 +716,7 @@ static struct xfrm_state *xfrm_state_construct(struct net *net,
if ((err = attach_auth_trunc(&x->aalg, &x->props.aalgo,
attrs[XFRMA_ALG_AUTH_TRUNC], extack)))
goto error;
- if (!x->props.aalgo) {
+ if (!x->aalg) {
if ((err = attach_auth(&x->aalg, &x->props.aalgo,
attrs[XFRMA_ALG_AUTH], extack)))
goto error;