[crypto] Reject zero-length IVs for GCM ciphers A zero-length IV is not permitted by the NIST GCM specification, since it would lead to leaking the authentication key. The only existing code path that can currently lead to the use of a GCM cipher with a zero-length initialisation vector is CMS decryption. Modifying a CMS encrypted message to include a zero-length IV would leak information required to obtain the authentication key into the transient decrypted image, but this transient image would then fail the GCM authentication tag check and so the decrypted plaintext would be immediately overwritten (with the re-encrypted ciphertext). Improve robustness by rejecting a zero-length initialisation vector for a GCM cipher, and add a test case to ensure that this rejection remains in place in future. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
boot from a web server via HTTP or HTTPS,
boot from an iSCSI, FCoE, or AoE SAN,
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.