[PATCH 5/7] cipher-gcm: assert 32 KiB input cap in gcm_ctr_encrypt
Jussi Kivilinna
jussi.kivilinna at iki.fi
Fri Jul 24 20:48:04 CEST 2026
* cipher/cipher-gcm.c (gcm_ctr_encrypt): Assert input length cap that
keeps CTR-wrap chunk math from overflowing.
--
gcm_ctr_encrypt handles the 32-bit CTR wrap by computing a chunk size
in u32 arithmetic that could overflow for a single multi-gigabyte
input. This was reported as a reachable assertion failure, but sole
caller gcm_crypt_inner caps input at 32 KiB for cache locality, so
num_ctr_increments and the chunk length stay small and the overflow
is unreachable. Assert the cap to document that instead of changing
the arithmetic.
Reported-by: JEAN Jeremy <Jeremy.Jean at ssi.gouv.fr>
Signed-off-by: Jussi Kivilinna <jussi.kivilinna at iki.fi>
---
cipher/cipher-gcm.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/cipher/cipher-gcm.c b/cipher/cipher-gcm.c
index c04683f8..e6a4df0f 100644
--- a/cipher/cipher-gcm.c
+++ b/cipher/cipher-gcm.c
@@ -815,6 +815,11 @@ gcm_ctr_encrypt (gcry_cipher_hd_t c, byte *outbuf, size_t outbuflen,
{
gcry_err_code_t err = 0;
+ /* Input is capped to 32KiB by gcm_crypt_inner() for better cache
+ * locality. As side-effect, CTR overflow checks below do not
+ * overflow. */
+ gcry_assert(inbuflen <= 32 * 1024);
+
while (inbuflen)
{
u32 nblocks_to_overflow;
--
2.53.0
More information about the Gcrypt-devel
mailing list