AES-GCM did not enforce limits on AAD length
NIST Special Publication 800-38D specifies that the bit length of the
AAD shall not exceed 2^64 - 1 bits. The implementation of AES-GCM in
libcrux-aesgcm neither enforced this limit for encryption nor for
decryption.
Impact
Use of AES-GCM with AAD of length exceeding the prescribed maximum
length degrades the authentication security of the GCM tag.
Mitigation
Starting from version 0.0.9 (published as libcrux-aes@v0.0.9),
limits on the length of the AAD input are enforced, so overlong AAD
inputs result in an error on encryption and decryption.
See advisory page for additional details.
libcrux-aesgcm0.0.7NIST Special Publication 800-38D specifies that the bit length of the
AAD shall not exceed
2^64 - 1bits. The implementation of AES-GCM inlibcrux-aesgcmneither enforced this limit for encryption nor fordecryption.
Impact
Use of AES-GCM with AAD of length exceeding the prescribed maximum
length degrades the authentication security of the GCM tag.
Mitigation
Starting from version
0.0.9(published aslibcrux-aes@v0.0.9),limits on the length of the AAD input are enforced, so overlong AAD
inputs result in an error on encryption and decryption.
See advisory page for additional details.