CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's MACsec implementation, specifically in the handling of packet sequence numbers (pn) during decryption. An attacker can exploit this flaw to replay captured frames indefinitely when the pn reaches its maximum value, potentially compromising the integrity of secure communications. Organizations using affected Linux systems, particularly those relying on MACsec for secure networking, should prioritize patching this vulnerability to mitigate the risk of replay attacks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: macsec: fix replay protection at XPN lower-PN wrap In macsec_post_decrypt(), when pn is U32_MAX, pn + 1 overflows u32 to 0 and the first branch never fires. If next_pn_halves.lower is also in the upper half, pn_same_half(pn, lower) is true and the XPN else-if does not fire either, leaving next_pn_halves unchanged. An attacker that captures the legitimate frame carrying pn == 0xFFFFFFFF on an XPN association can then replay it indefinitely, since lowest_pn never rises above the captured pn and macsec_decrypt() reconstructs the same IV. Extend the XPN else-if to also fire when pn + 1 wraps to 0, so receipt of pn == U32_MAX advances next_pn_halves to (upper + 1, 0).