crypto: af_alg - limit RX SG extraction by receive buffer budget

JIRA: https://redhat.atlassian.net/browse/RHEL-172207
CVE: CVE-2026-31677

Upstream Status: 8eceab19eba9dcbfd2a0daec72e1bf48aa100170

commit 8eceab19eba9dcbfd2a0daec72e1bf48aa100170
Author: Douya Le <ldy3087146292@gmail.com>
Date:   Thu Apr 2 23:34:55 2026 +0800

    crypto: af_alg - limit RX SG extraction by receive buffer budget

    Make af_alg_get_rsgl() limit each RX scatterlist extraction to the
    remaining receive buffer budget.

    af_alg_get_rsgl() currently uses af_alg_readable() only as a gate
    before extracting data into the RX scatterlist. Limit each extraction
    to the remaining af_alg_rcvbuf(sk) budget so that receive-side
    accounting matches the amount of data attached to the request.

    If skcipher cannot obtain enough RX space for at least one chunk while
    more data remains to be processed, reject the recvmsg call instead of
    rounding the request length down to zero.

    Fixes: e870456d8e ("crypto: algif_skcipher - overhaul memory management")
    Reported-by: Yifan Wu <yifanwucs@gmail.com>
    Reported-by: Juefei Pu <tomapufckgml@gmail.com>
    Co-developed-by: Yuan Tan <yuantan098@gmail.com>
    Signed-off-by: Yuan Tan <yuantan098@gmail.com>
    Suggested-by: Xin Liu <bird@lzu.edu.cn>
    Signed-off-by: Douya Le <ldy3087146292@gmail.com>
    Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
    Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>

Signed-off-by: Herbert Xu <herbert.xu@redhat.com>
This commit is contained in:
Herbert Xu
2026-05-01 21:54:01 +08:00
parent ada3d4ca44
commit 40240fa36e
2 changed files with 9 additions and 1 deletions
+2
View File
@@ -1135,6 +1135,8 @@ int af_alg_get_rsgl(struct sock *sk, struct msghdr *msg, int flags,
seglen = min_t(size_t, (maxsize - len),
msg_data_left(msg));
/* Never pin more pages than the remaining RX accounting budget. */
seglen = min_t(size_t, seglen, af_alg_rcvbuf(sk));
if (list_empty(&areq->rsgl_list)) {
rsgl = &areq->first_rsgl;
+7 -1
View File
@@ -82,8 +82,14 @@ static int _skcipher_recvmsg(struct socket *sock, struct msghdr *msg,
* If more buffers are to be expected to be processed, process only
* full block size buffers.
*/
if (ctx->more || len < ctx->used)
if (ctx->more || len < ctx->used) {
if (len < bs) {
err = -EINVAL;
goto free;
}
len -= len % bs;
}
/*
* Create a per request TX SGL for this request which tracks the