[PATCH net] wireguard: noise: reject responses for replaced initiations
From: Jérémy Jean
Date: Mon Oct 05 2026 - 16:38:01 EST
WireGuard can accept an old handshake response after starting a new
handshake. This reinstalls old keys and resets transport counters and
replay state, enabling nonce reuse, replay and packet forgery. This
breaks confidentiality and integrity guarantees.
Compare ephemeral secrets under the write lock to reject responses for
replaced initiations.
Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Jérémy Jean <Jeremy.Jean@xxxxxxxxxxxxxxxxx>
---
drivers/net/wireguard/noise.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireguard/noise.c b/drivers/net/wireguard/noise.c
index 9c0a09bf6c95..88cc9acc7dc7 100644
--- a/drivers/net/wireguard/noise.c
+++ b/drivers/net/wireguard/noise.c
@@ -784,10 +784,12 @@ wg_noise_handshake_consume_response(struct message_handshake_response *src,
/* Success! Copy everything to peer */
down_write(&handshake->lock);
- /* It's important to check that the state is still the same, while we
- * have an exclusive lock.
+ /* Check that this is still the initiation we authenticated against,
+ * while we have an exclusive lock.
*/
- if (handshake->state != state) {
+ if (handshake->state != state ||
+ crypto_memneq(handshake->ephemeral_private, ephemeral_private,
+ NOISE_PUBLIC_KEY_LEN)) {
up_write(&handshake->lock);
goto fail;
}
--
2.47.3