NIST Special Publication 800-38D specifies that the bit length of the
AAD shall not exceed 2^64 - 1 bits. The implementation of AES-GCM in
libcrux-aesgcm neither enforced this limit for encryption nor for
decryption.
Use of AES-GCM with AAD of length exceeding the prescribed maximum length degrades the authentication security of the GCM tag.
Starting from version 0.0.9 (published as libcrux-aes@v0.0.9),
limits on the length of the AAD input are enforced, so overlong AAD
inputs result in an error on encryption and decryption.
{
"license": "CC0-1.0"
}{
"affects": {
"os": [],
"functions": [
"libcrux_aesgcm::AesGcm128Key::decrypt",
"libcrux_aesgcm::AesGcm128Key::encrypt",
"libcrux_aesgcm::AesGcm256Key::decrypt",
"libcrux_aesgcm::AesGcm256Key::encrypt",
"libcrux_aesgcm::aes_gcm_128::AesGcm128::decrypt",
"libcrux_aesgcm::aes_gcm_128::AesGcm128::encrypt",
"libcrux_aesgcm::aes_gcm_128::Key::decrypt",
"libcrux_aesgcm::aes_gcm_128::Key::encrypt",
"libcrux_aesgcm::aes_gcm_128::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_128::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_128::neon::Key::decrypt",
"libcrux_aesgcm::aes_gcm_128::neon::Key::encrypt",
"libcrux_aesgcm::aes_gcm_128::neon::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_128::neon::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_128::neon::NeonAesGcm128::decrypt",
"libcrux_aesgcm::aes_gcm_128::neon::NeonAesGcm128::encrypt",
"libcrux_aesgcm::aes_gcm_128::portable::Key::decrypt",
"libcrux_aesgcm::aes_gcm_128::portable::Key::encrypt",
"libcrux_aesgcm::aes_gcm_128::portable::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_128::portable::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_128::portable::PortableAesGcm128::decrypt",
"libcrux_aesgcm::aes_gcm_128::portable::PortableAesGcm128::encrypt",
"libcrux_aesgcm::aes_gcm_128::x64::Key::decrypt",
"libcrux_aesgcm::aes_gcm_128::x64::Key::encrypt",
"libcrux_aesgcm::aes_gcm_128::x64::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_128::x64::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_128::x64::X64AesGcm128::decrypt",
"libcrux_aesgcm::aes_gcm_128::x64::X64AesGcm128::encrypt",
"libcrux_aesgcm::aes_gcm_256::AesGcm256::decrypt",
"libcrux_aesgcm::aes_gcm_256::AesGcm256::encrypt",
"libcrux_aesgcm::aes_gcm_256::Key::decrypt",
"libcrux_aesgcm::aes_gcm_256::Key::encrypt",
"libcrux_aesgcm::aes_gcm_256::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_256::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_256::neon::Key::decrypt",
"libcrux_aesgcm::aes_gcm_256::neon::Key::encrypt",
"libcrux_aesgcm::aes_gcm_256::neon::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_256::neon::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_256::neon::NeonAesGcm256::decrypt",
"libcrux_aesgcm::aes_gcm_256::neon::NeonAesGcm256::encrypt",
"libcrux_aesgcm::aes_gcm_256::portable::Key::decrypt",
"libcrux_aesgcm::aes_gcm_256::portable::Key::encrypt",
"libcrux_aesgcm::aes_gcm_256::portable::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_256::portable::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_256::portable::PortableAesGcm256::decrypt",
"libcrux_aesgcm::aes_gcm_256::portable::PortableAesGcm256::encrypt",
"libcrux_aesgcm::aes_gcm_256::x64::Key::decrypt",
"libcrux_aesgcm::aes_gcm_256::x64::Key::encrypt",
"libcrux_aesgcm::aes_gcm_256::x64::KeyRef::decrypt",
"libcrux_aesgcm::aes_gcm_256::x64::KeyRef::encrypt",
"libcrux_aesgcm::aes_gcm_256::x64::X64AesGcm256::decrypt",
"libcrux_aesgcm::aes_gcm_256::x64::X64AesGcm256::encrypt"
],
"arch": []
},
"affected_functions": null
}