Re: [PATCH] crypto: algif_skcipher: rewind rounded output bytes
From: Herbert Xu
Date: Thu Oct 08 2026 - 04:41:31 EST
On Sun, Oct 04, 2026 at 02:09:46PM +0900, Daehyeon Ko wrote:
> af_alg_get_rsgl() advances the receive iterator by the unrounded RX
> scatterlist length. For a continuing skcipher request,
> _skcipher_recvmsg() then rounds its local length down to a whole chunksize
> without restoring the iterator.
>
> A later chunk starts after bytes which the provider never wrote, while the
> syscall returns only the processed length. When copy_splice_read()
> supplies non-zeroed pages and publishes that return as a dense prefix, the
> gap exposes stale bytes from a previous page lifetime.
>
> With unprivileged xts(aes), a 31-byte MSG_MORE request followed by one
> final byte advances a 47-byte destination while returning 32 bytes. A
> hardened v7.2-rc5 image retained all 15 seeded stale bytes in 4,829 of
> 4,829 records. With init_on_alloc enabled, all 72,345 gap bytes observed
> were zero.
>
> Rewind the iterator by the tail excluded during rounding, before rejecting
> a zero processed length. The crypto request uses only the rounded length;
> af_alg_free_resources() releases the entire RX list before another receive
> iteration.
>
> The fixed target-like kernel returned byte-identical dense 48-byte output
> in 4,771 of 4,771 rounds. The unmodified kernel returned the vulnerable
> 32-byte short record in 2,409 of 2,409 rounds.
>
> Fixes: e870456d8e7c ("crypto: algif_skcipher - overhaul memory management")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Daehyeon Ko <4ncienth@xxxxxxxxx>
> ---
> crypto/algif_skcipher.c | 8 ++++++--
> 1 file changed, 6 insertions(+), 2 deletions(-)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt