Re: [PATCH] tipc: prevent GCM nonce reuse on peer key changes

From: patchwork-bot+netdevbpf

Date: Mon Sep 28 2026 - 21:41:52 EST


Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:

On Thu, 24 Sep 2026 20:21:05 +0000 you wrote:
> TIPC can encrypt traffic between nodes using a different transmit key
> for each node. In this mode, the AES-GCM nonce for a packet sent to a
> known peer consists of a 32-bit prefix (a per-key salt XOR the peer's
> address) followed by a 64-bit counter. That counter is stored in the
> peer's RX crypto object. When the peer reports a change in which key
> it uses to receive packets, TIPC resets this counter. The sender can
> still be using the same TX key and salt, so subsequent packets reuse
> earlier nonces. This nonce reuse breaks confidentiality and exposes
> GCM's authentication key. This makes forgeries trivial: an attacker
> can exploit CTR malleability to alter captured ciphertexts and use the
> recovered authentication key to compute a valid tag for the modified
> ciphertext, under the same key and nonce.
>
> [...]

Here is the summary with links:
- tipc: prevent GCM nonce reuse on peer key changes
https://git.kernel.org/netdev/net/c/512ccd3d0e91

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html