)]}'
{
  "commit": "af3ff8045bbf3e32f1a448542e73abb4c8ceb6f1",
  "tree": "c6201b05bafc29103a179e0f2d14c82d23866818",
  "parents": [
    "887207ed9e5812ed9239b6d07185a2d35dda91db"
  ],
  "author": {
    "name": "Eric Biggers",
    "email": "ebiggers@google.com",
    "time": "Tue Nov 28 18:01:38 2017 -0800"
  },
  "committer": {
    "name": "Herbert Xu",
    "email": "herbert@gondor.apana.org.au",
    "time": "Wed Nov 29 13:39:15 2017 +1100"
  },
  "message": "crypto: hmac - require that the underlying hash algorithm is unkeyed\n\nBecause the HMAC template didn\u0027t check that its underlying hash\nalgorithm is unkeyed, trying to use \"hmac(hmac(sha3-512-generic))\"\nthrough AF_ALG or through KEYCTL_DH_COMPUTE resulted in the inner HMAC\nbeing used without having been keyed, resulting in sha3_update() being\ncalled without sha3_init(), causing a stack buffer overflow.\n\nThis is a very old bug, but it seems to have only started causing real\nproblems when SHA-3 support was added (requires CONFIG_CRYPTO_SHA3)\nbecause the innermost hash\u0027s state is -\u003eimport()ed from a zeroed buffer,\nand it just so happens that other hash algorithms are fine with that,\nbut SHA-3 is not.  However, there could be arch or hardware-dependent\nhash algorithms also affected; I couldn\u0027t test everything.\n\nFix the bug by introducing a function crypto_shash_alg_has_setkey()\nwhich tests whether a shash algorithm is keyed.  Then update the HMAC\ntemplate to require that its underlying hash algorithm is unkeyed.\n\nHere is a reproducer:\n\n    #include \u003clinux/if_alg.h\u003e\n    #include \u003csys/socket.h\u003e\n\n    int main()\n    {\n        int algfd;\n        struct sockaddr_alg addr \u003d {\n            .salg_type \u003d \"hash\",\n            .salg_name \u003d \"hmac(hmac(sha3-512-generic))\",\n        };\n        char key[4096] \u003d { 0 };\n\n        algfd \u003d socket(AF_ALG, SOCK_SEQPACKET, 0);\n        bind(algfd, (const struct sockaddr *)\u0026addr, sizeof(addr));\n        setsockopt(algfd, SOL_ALG, ALG_SET_KEY, key, sizeof(key));\n    }\n\nHere was the KASAN report from syzbot:\n\n    BUG: KASAN: stack-out-of-bounds in memcpy include/linux/string.h:341  [inline]\n    BUG: KASAN: stack-out-of-bounds in sha3_update+0xdf/0x2e0  crypto/sha3_generic.c:161\n    Write of size 4096 at addr ffff8801cca07c40 by task syzkaller076574/3044\n\n    CPU: 1 PID: 3044 Comm: syzkaller076574 Not tainted 4.14.0-mm1+ #25\n    Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS  Google 01/01/2011\n    Call Trace:\n      __dump_stack lib/dump_stack.c:17 [inline]\n      dump_stack+0x194/0x257 lib/dump_stack.c:53\n      print_address_description+0x73/0x250 mm/kasan/report.c:252\n      kasan_report_error mm/kasan/report.c:351 [inline]\n      kasan_report+0x25b/0x340 mm/kasan/report.c:409\n      check_memory_region_inline mm/kasan/kasan.c:260 [inline]\n      check_memory_region+0x137/0x190 mm/kasan/kasan.c:267\n      memcpy+0x37/0x50 mm/kasan/kasan.c:303\n      memcpy include/linux/string.h:341 [inline]\n      sha3_update+0xdf/0x2e0 crypto/sha3_generic.c:161\n      crypto_shash_update+0xcb/0x220 crypto/shash.c:109\n      shash_finup_unaligned+0x2a/0x60 crypto/shash.c:151\n      crypto_shash_finup+0xc4/0x120 crypto/shash.c:165\n      hmac_finup+0x182/0x330 crypto/hmac.c:152\n      crypto_shash_finup+0xc4/0x120 crypto/shash.c:165\n      shash_digest_unaligned+0x9e/0xd0 crypto/shash.c:172\n      crypto_shash_digest+0xc4/0x120 crypto/shash.c:186\n      hmac_setkey+0x36a/0x690 crypto/hmac.c:66\n      crypto_shash_setkey+0xad/0x190 crypto/shash.c:64\n      shash_async_setkey+0x47/0x60 crypto/shash.c:207\n      crypto_ahash_setkey+0xaf/0x180 crypto/ahash.c:200\n      hash_setkey+0x40/0x90 crypto/algif_hash.c:446\n      alg_setkey crypto/af_alg.c:221 [inline]\n      alg_setsockopt+0x2a1/0x350 crypto/af_alg.c:254\n      SYSC_setsockopt net/socket.c:1851 [inline]\n      SyS_setsockopt+0x189/0x360 net/socket.c:1830\n      entry_SYSCALL_64_fastpath+0x1f/0x96\n\nReported-by: syzbot \u003csyzkaller@googlegroups.com\u003e\nCc: \u003cstable@vger.kernel.org\u003e\nSigned-off-by: Eric Biggers \u003cebiggers@google.com\u003e\nSigned-off-by: Herbert Xu \u003cherbert@gondor.apana.org.au\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "92871dc2a63ec66ca628df3a44b025b7ef6f247e",
      "old_mode": 33188,
      "old_path": "crypto/hmac.c",
      "new_id": "e74730224f0a5f6346bb8ae7b80f3ed5e6cb6281",
      "new_mode": 33188,
      "new_path": "crypto/hmac.c"
    },
    {
      "type": "modify",
      "old_id": "325a14da58278f01b8c1ffd92bdd8990db2860c4",
      "old_mode": 33188,
      "old_path": "crypto/shash.c",
      "new_id": "e849d3ee2e2728d346df1f21f6a8d4db57fc42c5",
      "new_mode": 33188,
      "new_path": "crypto/shash.c"
    },
    {
      "type": "modify",
      "old_id": "f0b44c16e88f241721a4296019475abae6b7a3b0",
      "old_mode": 33188,
      "old_path": "include/crypto/internal/hash.h",
      "new_id": "c2bae8da642cbaef97f3de444a446a27df15dc18",
      "new_mode": 33188,
      "new_path": "include/crypto/internal/hash.h"
    }
  ]
}
