Thread (28 messages) 28 messages, 4 authors, 14d ago
COOLING14d

Revision v10 of 7 in this series.

Revisions (7)
  1. v3 [diff vs current]
  2. v4 [diff vs current]
  3. v5 [diff vs current]
  4. v3 [diff vs current]
  5. v9 [diff vs current]
  6. v10 current
  7. v11 [diff vs current]

[PATCH net v10 11/14] afs: Fix creation of RxGK CM channel token to have right size

From: David Howells <dhowells@redhat.com>
Date: 2026-09-14 15:14:49
Also in: lkml, stable
Subsystem: afs filesystem, filesystems (vfs and infrastructure), the rest · Maintainers: David Howells, Marc Dionne, Alexander Viro, Christian Brauner, Linus Torvalds

Fix afs_create_yfs_cm_token() so that it calculates the token size
correctly, remembering to add in the 4 bytes of the level.

As it happens, this bug has no effect because crypto_krb5_how_much_buffer()
rounds encsize up to a multiple of the crypto block size (16 or 32) before
adding on the checksum size - and so there's actually 8 bytes of unused
space allocated within the blob-to-be-encrypted and 4 bytes of that gets
used.

Fixes: d98c317fd9aa ("afs: Use rxgk RESPONSE to pass token for callback channel")
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824091645.415423-1-dhowells%40redhat.com
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Marc Dionne <marc.dionne@auristor.com>
cc: Eric Dumazet <edumazet@google.com>
cc: "David S. Miller" <davem@davemloft.net>
cc: Jakub Kicinski <kuba@kernel.org>
cc: Paolo Abeni <pabeni@redhat.com>
cc: Simon Horman <horms@kernel.org>
cc: linux-afs@lists.infradead.org
cc: stable@vger.kernel.org
---
 fs/afs/cm_security.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/afs/cm_security.c b/fs/afs/cm_security.c
index 103168c70dd4..5eeeef761cf3 100644
--- a/fs/afs/cm_security.c
+++ b/fs/afs/cm_security.c
@@ -235,7 +235,7 @@ static int afs_create_yfs_cm_token(struct sk_buff *challenge,
 	 *	struct RXGK_AuthName	identities<>;
 	 * };
 	 */
-	toksize = keysize + 8 + 4 + 4 + 8 + xdr_len_object(authsize);
+	toksize = keysize + 4 + 8 + 4 + 4 + 8 + xdr_len_object(authsize);
 
 	offset = 0;
 	encsize = crypto_krb5_how_much_buffer(token_krb5, KRB5_ENCRYPT_MODE, toksize, &offset);
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help