Commit f7db0e6d62 for openssl.org
commit f7db0e6d62827d1309a3833f79cbd77a9bec32ed
Author: Billy Brumley <bbb@iki.fi>
Date: Thu Sep 17 18:49:54 2026 -0400
ASCON: reject AEAD Update and Final on a finished context
The context was never marked finished after Final, so it kept accepting
data and would issue a tag for it. Mark it finished once the tag has been
computed or verified, matching the other AEADs.
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Merge-date: Thu Oct 1 19:07:28 2026
Merged-from: https://github.com/openssl/openssl/pull/32875
diff --git a/providers/implementations/ciphers/cipher_ascon_aead128.c b/providers/implementations/ciphers/cipher_ascon_aead128.c
index be28b49a7d..281c5c2ca7 100644
--- a/providers/implementations/ciphers/cipher_ascon_aead128.c
+++ b/providers/implementations/ciphers/cipher_ascon_aead128.c
@@ -337,6 +337,7 @@ static int ascon_aead128_final(void *vctx, unsigned char *out, size_t *outl, siz
ciphertext, tag, tag_len);
*outl = ret;
ctx->is_tag_set = 1;
+ ctx->is_ongoing = 0; /* finished: no further update/final on this IV */
return 1;
} else if (ctx->direction == DECRYPTION) {
@@ -352,6 +353,7 @@ static int ascon_aead128_final(void *vctx, unsigned char *out, size_t *outl, siz
plaintext, &is_tag_valid,
expected_tag,
expected_tag_len);
+ ctx->is_ongoing = 0; /* finished, whatever the verdict */
if (is_tag_valid) {
*outl = ret;