| From 2ef722ad96bb48fe4865c8ea3840ca9b0209427c Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Wed, 18 May 2022 08:32:18 +0200 |
| Subject: net: af_key: check encryption module availability consistency |
| |
| From: Thomas Bartschies <thomas.bartschies@cvk.de> |
| |
| [ Upstream commit 015c44d7bff3f44d569716117becd570c179ca32 ] |
| |
| Since the recent introduction supporting the SM3 and SM4 hash algos for IPsec, the kernel |
| produces invalid pfkey acquire messages, when these encryption modules are disabled. This |
| happens because the availability of the algos wasn't checked in all necessary functions. |
| This patch adds these checks. |
| |
| Signed-off-by: Thomas Bartschies <thomas.bartschies@cvk.de> |
| Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/key/af_key.c | 6 +++--- |
| 1 file changed, 3 insertions(+), 3 deletions(-) |
| |
| diff --git a/net/key/af_key.c b/net/key/af_key.c |
| index 61505b0df57d..6b7ed5568c09 100644 |
| --- a/net/key/af_key.c |
| +++ b/net/key/af_key.c |
| @@ -2904,7 +2904,7 @@ static int count_ah_combs(const struct xfrm_tmpl *t) |
| break; |
| if (!aalg->pfkey_supported) |
| continue; |
| - if (aalg_tmpl_set(t, aalg)) |
| + if (aalg_tmpl_set(t, aalg) && aalg->available) |
| sz += sizeof(struct sadb_comb); |
| } |
| return sz + sizeof(struct sadb_prop); |
| @@ -2922,7 +2922,7 @@ static int count_esp_combs(const struct xfrm_tmpl *t) |
| if (!ealg->pfkey_supported) |
| continue; |
| |
| - if (!(ealg_tmpl_set(t, ealg))) |
| + if (!(ealg_tmpl_set(t, ealg) && ealg->available)) |
| continue; |
| |
| for (k = 1; ; k++) { |
| @@ -2933,7 +2933,7 @@ static int count_esp_combs(const struct xfrm_tmpl *t) |
| if (!aalg->pfkey_supported) |
| continue; |
| |
| - if (aalg_tmpl_set(t, aalg)) |
| + if (aalg_tmpl_set(t, aalg) && aalg->available) |
| sz += sizeof(struct sadb_comb); |
| } |
| } |
| -- |
| 2.35.1 |
| |