Re: [PATCH v2] crypto: x86/aes-gcm - fix always true check for last AAD segment
From: Eric Biggers
Date: Sat Sep 26 2026 - 13:26:41 EST
On Sat, Sep 26, 2026 at 08:29:03PM +0530, Mohamad Raizudeen wrote:
> In gcm_process_assoc(), a segment that is not the last one must have its
> length rounded down to a multiple of 16 bytes, as required by the
> assembly. The check for a non-last segment is `if (unlikely(assoclen))
> /* Not the last segment yet? */` where assoclen is the number of AAD
> bytes remaining after the current segment.
>
> Since the conversion to the new scatterwalk API, assoclen is decremented
> at the end of the loop body rather than the beginning, so it still
> includes the current segment when the check executes, making the check
> always true.
>
> As a result the last segment was rounded down as well, causing some
> avoidable extra work: an additional memcpy into the temporary buffer and
> an additional call into the assembly afte the loop. The GCM
> authentication tag is unaffected either way, so the self-tests pass and
> this went unnoticed. It is purely an efficiency issue rather than a
> correctness one.
>
> Fix this by moving the assoclen decrement back to the beginning of the
> loop body.
>
> Fixes: e9787deff49ea ("crypto: x86/aes-gcm - use the new scatterwalk functions")
> Cc: stable@xxxxxxxxxxxxxxx
> Suggested-by: Eric Biggers <ebiggers@xxxxxxxxxx>
> Signed-off-by: Mohamad Raizudeen <raizudeen.kerneldev@xxxxxxxxx>
Applied to https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git/log/?h=libcrypto-fixes
Thanks!
- Eric