Commit d0305f8d9002 for kernel

commit d0305f8d90029556260c6824b61c493c424eba9e
Author: Jason A. Donenfeld <Jason@zx2c4.com>
Date:   Thu Oct 8 14:59:16 2026 +0200

    wireguard: noise: reject response consumption after intermediate initiation

    Two threads begin processing the identical response message, received
    twice. The first thread, A, runs. While it's running, the second one,
    B, gets partway through, and during that slow calculation, or even while
    blocking on down_write(), A completes and then also a handshake
    initiation that's already been queued up runs in thread C, which itself
    takes that same down_write(). The handshake initiation creation
    succeeds, and sets the state back to waiting-for-response, and calls
    up_write(), at which point thread B resumes, because either its finished
    its calculations or was finally allowed to acquire down_write(). Thread
    B then copies the state back to the peer, and begins a new session,
    using that state, which is the same session as the one made in thread A.

    Thread A                        Thread B                        Thread C

    down_read()
     sA = handshake->state
     memcpy(cA, handshake->crypto)
    up_read()
    if (sA != 1)
     goto fail
    slow_crypto(cA)
                                    down_read()
                                     sB = handshake->state
                                     memcpy(cB, handshake->crypto)
                                    up_read()
                                    if (sB != 1)
                                     goto fail
                                    slow_crypto(cB)
    down_write()
     if (sA != handshake->state)
      goto fail
     memcpy(handshake->crypto, cA)
     handshake->state = 2
    up_write()
    down_write()
     if (handshake->state != 2)
      goto fail
     derive_session(handshake->crypto)
    up_write()
                                                                    down_write()
                                                                     slow_crypto(handshake->crypto)
                                                                     handshake->state = 1
                                                                    up_write()
                                    down_write()
                                     if (sB != handshake->state)
                                       goto fail
                                     memcpy(handshake->crypto, cB)
                                     handshake->state = 2
                                    up_write()
                                    down_write()
                                     if (handshake->state != 2)
                                      goto fail
                                     derive_session(handshake->crypto)
                                    up_write()

    This seems basically impossible to hit in a meaningful way in practice,
    but ensure that it absolutely cannot happen by comparing the ephemeral
    private key that's on the stack with the latest one that the peer's
    handshake state has.

    Cc: stable@vger.kernel.org
    Fixes: e7096c131e51 ("net: WireGuard secure network tunnel")
    Reported-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
    Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
    Link: https://patch.msgid.link/20261008130124.724119-4-Jason@zx2c4.com
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/drivers/net/wireguard/noise.c b/drivers/net/wireguard/noise.c
index 9c0a09bf6c95..ec2513d6dfab 100644
--- a/drivers/net/wireguard/noise.c
+++ b/drivers/net/wireguard/noise.c
@@ -784,10 +784,11 @@ wg_noise_handshake_consume_response(struct message_handshake_response *src,

 	/* Success! Copy everything to peer */
 	down_write(&handshake->lock);
-	/* It's important to check that the state is still the same, while we
-	 * have an exclusive lock.
+	/* Check that the state is the same and that this is still the
+	 * initiation we started with, while we have an exclusive lock.
 	 */
-	if (handshake->state != state) {
+	if (handshake->state != state ||
+	    crypto_memneq(handshake->ephemeral_private, ephemeral_private, NOISE_PUBLIC_KEY_LEN)) {
 		up_write(&handshake->lock);
 		goto fail;
 	}