On Fri, Jun 23, 2017 at 04:48:51AM -0400, Jan Stancek wrote: > > So I take it my workaround patch [1] is not acceptable in > short-term as well? > > [1] http://marc.info/?l=linux-crypto-vger&m=149373371023377 As we don't have a proper fix we may not be aware of the complete scope of the problem (e.g., the overrun may go beyond 3 blocks). As this is code that is exposed to remote entities, it would be safest to disable it until we get a proper fix. Thanks, -- Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt