Rust Short Gcm Auth Tag
Description
This detector identifies Rust code that encrypts data with an AEAD cipher (AES-GCM, CCM, EAX, OCB3 or ChaCha20-Poly1305) using an authentication tag shorter than the recommended minimum. A truncated tag lowers the cost of forging ciphertexts, so an attacker can tamper with encrypted data and have it accepted as authentic, compromising its integrity.
Detection Strategy
• The code must import the openssl crate or one of the RustCrypto AEAD crates (aes_gcm, ccm, eax, ocb3)
• For openssl, the detector examines calls to encrypt_aead and resolves the cipher argument (e.g., Cipher::aes_256_gcm()) and the tag buffer argument
• A vulnerability is reported when the tag buffer is a fixed-size array shorter than 12 bytes (96 bits), or shorter than 16 bytes (128 bits) for ChaCha20-Poly1305; the length can be a literal or a constant
• For RustCrypto, the detector examines new and new_from_slice constructor calls, either with explicit type parameters or through a type alias
• A vulnerability is reported when the tag-size type parameter (e.g., U8 or U4) is shorter than 12 bytes
• Tag buffers received as function parameters, or tag sizes that cannot be resolved statically, are not reported
Vulnerable code example
use aes::Aes128;
use aes_gcm::aead::consts::{U12, U8};
use aes_gcm::aead::{Aead, KeyInit, Nonce};
use aes_gcm::AesGcm;
use openssl::symm::{encrypt_aead, Cipher};
fn encrypt_openssl(key: &[u8], iv: &[u8], aad: &[u8], data: &[u8]) -> (Vec<u8>, Vec<u8>) {
// VULNERABLE: the tag buffer is 8 bytes (64 bits), below the 12-byte floor...✅ Secure code example
use aes::Aes128;
use aes_gcm::aead::consts::{U12, U16};
use aes_gcm::aead::{Aead, KeyInit, Nonce};
use aes_gcm::AesGcm;
use openssl::symm::{encrypt_aead, Cipher};
fn encrypt_openssl(key: &[u8], iv: &[u8], aad: &[u8], data: &[u8]) -> (Vec<u8>, Vec<u8>) {
// SAFE: the tag buffer is 16 bytes (128 bits)...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, fill out this contact form.