diff options
author | Eric Biggers <ebiggers@google.com> | 2021-08-24 22:59:18 -0700 |
---|---|---|
committer | Jens Axboe <axboe@kernel.dk> | 2021-08-25 06:45:00 -0600 |
commit | cc40b7225151f611ef837f6403cfaeadc7af214a (patch) | |
tree | 6713d8262cd0bfc78c465b51bf00b78fc7fb2e9a | |
parent | 4d643b66089591b4769bcdb6fd1bfeff2fe301b8 (diff) | |
download | linux-cc40b7225151f611ef837f6403cfaeadc7af214a.tar.bz2 |
blk-crypto: fix check for too-large dun_bytes
dun_bytes needs to be less than or equal to the IV size of the
encryption mode, not just less than or equal to BLK_CRYPTO_MAX_IV_SIZE.
Currently this doesn't matter since blk_crypto_init_key() is never
actually passed invalid values, but we might as well fix this.
Fixes: a892c8d52c02 ("block: Inline encryption support for blk-mq")
Signed-off-by: Eric Biggers <ebiggers@google.com>
Link: https://lore.kernel.org/r/20210825055918.51975-1-ebiggers@kernel.org
Signed-off-by: Jens Axboe <axboe@kernel.dk>
-rw-r--r-- | block/blk-crypto.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/block/blk-crypto.c b/block/blk-crypto.c index c5bdaafffa29..103c2e2d50d6 100644 --- a/block/blk-crypto.c +++ b/block/blk-crypto.c @@ -332,7 +332,7 @@ int blk_crypto_init_key(struct blk_crypto_key *blk_key, const u8 *raw_key, if (mode->keysize == 0) return -EINVAL; - if (dun_bytes == 0 || dun_bytes > BLK_CRYPTO_MAX_IV_SIZE) + if (dun_bytes == 0 || dun_bytes > mode->ivsize) return -EINVAL; if (!is_power_of_2(data_unit_size)) |