From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 099D02BE043; Fri, 7 Aug 2026 13:54:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786110896; cv=none; b=QEzvVnrD1d6YjNwJKOQXcjpf+zX7/RfASTuZtvTlIQha4R3llwocVuDN+8+8qq1Um4MjOj/R8ZhDAfyPGvIDM6FwjGB6U/UQanjY15+fkXaTWzpvZXXKSBHu4QQj6fK3fvAHQ2diyJVuBRjv1NL+Y2LVJzDBphBEvhLLHdOmfXQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786110896; c=relaxed/simple; bh=TnhvjgQ+Napyf0PkgUQSG8OwkfMCu8KVyYlywY/C8GQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Hiu0DO+6hHKSeKB1NF5hs+k1JEfFdUF/4zYWNlxw3gDtprgCGQuNCY7rnJCNgceqV18Y0FnpOB90HOfyb7vAEHbFyU48Oe5Mj6YhSCJmeVPqi/+wGlozE7m5wRqavu2o9EK1XqvF4ryPdDWLgYV5Ts1bI+7+B/CuywMKt5rB6TI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=LQnp7l+b; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="LQnp7l+b" Received: from pps.filterd (m0353729.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 677Clixu3829316; Fri, 7 Aug 2026 13:54:46 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=OZ11EtV2mZPb2QIVq 17a/epK2LrZ4cxZ64YassYOTyY=; b=LQnp7l+bTK2zGgih7H53y8A6a5KG2u9na wItdV2JePVA591NnkJ2b9bNo6jmUHTXteh/L9eqV0e11HISU7iRSqjdwYpc269DM /5n1fmmnFNcxL97F5EEcdmtSIqfvaQf9Watrz6TQVcGRxvNBzDQRMoizB9AkACEE iNC/waYpnbtM5KtUjFBzejB6DjbFcV6EU/33aBkL+xqll4cElCJvSq39YlgnPbKc xg4mIoXmWzbBcZuBQTUhco0XWlntCPq197at2JCQJ9BXTbF5gxAMOe6EG+hkTVCA yIn//XJl4cVetUYVX3w8G3gvb4sBHB7Nx27g2+rJtv4PdQfbJw39Q== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fvy01m5sf-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 13:54:46 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 677DfLef007618; Fri, 7 Aug 2026 13:54:45 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fsvmhquen-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 13:54:45 +0000 (GMT) Received: from smtpav02.fra02v.mail.ibm.com (smtpav02.fra02v.mail.ibm.com [10.20.54.101]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 677DsfTX31981826 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 7 Aug 2026 13:54:41 GMT Received: from smtpav02.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3843A2005A; Fri, 7 Aug 2026 13:54:41 +0000 (GMT) Received: from smtpav02.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 139362004E; Fri, 7 Aug 2026 13:54:41 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.146.84]) by smtpav02.fra02v.mail.ibm.com (Postfix) with ESMTP; Fri, 7 Aug 2026 13:54:41 +0000 (GMT) From: Harald Freudenberger To: dengler@linux.ibm.com, fcallies@linux.ibm.com, ifranzki@linux.ibm.com Cc: freude@linux.ibm.com, linux-s390@vger.kernel.org, Heiko Carstens , Vasily Gorbik , Alexander Gordeev , linux-crypto@vger.kernel.org Subject: [PATCH v3 1/3] s390/crypto: Fix skcipher_walk return code handling in aes_s390 Date: Fri, 7 Aug 2026 15:54:38 +0200 Message-ID: <20260807135440.35888-2-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260807135440.35888-1-freude@linux.ibm.com> References: <20260807135440.35888-1-freude@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-s390@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-GUID: zNyNGsGlaOmXxSsxxnZvmfZZVCD7euIB X-Proofpoint-Spam-Info: AW1haW4tMjYwODA3MDEwOCBTYWx0ZWRfXz87HU7IuP0n0 /597HEOYkfAPAd50XPyrnWNqNQH9glszIiBNOIbkkgWdzbokHrVgbDdxZCDJ8rNlxn1n+U3eQ7u KGUIYBibyg9aXBwBF5/66KcdMDO+UBo= X-Proofpoint-ORIG-GUID: zNyNGsGlaOmXxSsxxnZvmfZZVCD7euIB X-Authority-Analysis: v=2.4 cv=afNRWxot c=1 sm=1 tr=0 ts=6a75e3a6 cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=uAbxVGIbfxUO_5tXvNgY:22 a=VnNF1IyMAAAA:8 a=VwQbUJbxAAAA:8 a=CBD_y4w3mMu2BuU9sPoA:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA3MDEwOCBTYWx0ZWRfX7YCbF2Ka6vCh 9De4+eX0srHIi8aqVg3QrNAKpJJzd7EGOYSg3bBZVECEEXEfPLWPNYA0PyVRpdrCMSYQc0GorJt jtP9hDwTLK3dlnekwZg9wxCU6hMT6xF3aqFtjmlOa2V5YOYI3hgdU6KZVQwBQ12DHH+L0BsZkUO iJb2VtS7p7OB+NDJUIs/m37chUKDb0IR/B1l+Ur5M42qO6t3XoooP/k43z7jidVNvxFc2cx2MYu WpZ9dlrY3d5dOAzjY8AzxXiSGFoBBha5dHh9d2Ei7VGTyHTdjMSv2k5QcImnloYvZhSRdt05gDd ThHTKfBgTsHvwCnBYiWaVJDJ14ucYM3CUzV9EGEoDIyPrQ1piS/5Mod6VdPI/UUlXspmR+68ZEs EDcBVdmtdbGPcAO1A5dZEjl+X9/UV585jDK3rlBlOZ1p8Wmo1KkxWuQHUuvQze6XtGhwJK8UVKE 8Yn251vkAY1uPMQeOAQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-07_02,2026-08-06_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 spamscore=0 phishscore=0 impostorscore=0 adultscore=0 suspectscore=0 bulkscore=0 clxscore=1015 priorityscore=1501 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608070108 The return codes from skcipher_walk_virt() were not properly checked before entering the processing loops in ecb_aes_crypt() and ctr_aes_crypt(). If skcipher_walk_virt() fails, the walk structure may be in an undefined state, and attempting to process data could lead to incorrect behavior or accessing uninitialized memory. Add proper return code checking to ensure correct handling of the walk initialization and walk advance and eventually return to the caller with that return code. Fixes: 7988fb2c03c8 ("crypto: s390/aes - convert to skcipher API") Signed-off-by: Harald Freudenberger Cc: stable@vger.kernel.org # 5.5+ --- arch/s390/crypto/aes_s390.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/arch/s390/crypto/aes_s390.c b/arch/s390/crypto/aes_s390.c index 62edc66d5478..366ce22d3623 100644 --- a/arch/s390/crypto/aes_s390.c +++ b/arch/s390/crypto/aes_s390.c @@ -129,7 +129,7 @@ static int ecb_aes_crypt(struct skcipher_request *req, unsigned long modifier) return fallback_skcipher_crypt(sctx, req, modifier); ret = skcipher_walk_virt(&walk, req, false); - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_km(sctx->fc | modifier, sctx->key, @@ -233,7 +233,7 @@ static int cbc_aes_crypt(struct skcipher_request *req, unsigned long modifier) return ret; memcpy(param.iv, walk.iv, AES_BLOCK_SIZE); memcpy(param.key, sctx->key, sctx->key_len); - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_kmc(sctx->fc | modifier, ¶m, @@ -359,7 +359,7 @@ static int xts_aes_crypt(struct skcipher_request *req, unsigned long modifier) memcpy(xts_param.key + offset, xts_ctx->key, xts_ctx->key_len); memcpy(xts_param.init, pcc_param.xts, 16); - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_km(xts_ctx->fc | modifier, xts_param.key + offset, @@ -487,7 +487,7 @@ static int fullxts_aes_crypt(struct skcipher_request *req, unsigned long modifi memcpy(fxts_param.tweak, req->iv, AES_BLOCK_SIZE); fxts_param.nap[0] = 0x01; /* initial alpha power (1, little-endian) */ - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_km(xts_ctx->fc | modifier, fxts_param.key + offset, @@ -577,7 +577,7 @@ static int ctr_aes_crypt(struct skcipher_request *req) locked = mutex_trylock(&ctrblk_lock); ret = skcipher_walk_virt(&walk, req, false); - while ((nbytes = walk.nbytes) >= AES_BLOCK_SIZE) { + while (!ret && ((nbytes = walk.nbytes) >= AES_BLOCK_SIZE)) { n = AES_BLOCK_SIZE; if (nbytes >= 2*AES_BLOCK_SIZE && locked) @@ -596,7 +596,7 @@ static int ctr_aes_crypt(struct skcipher_request *req) /* * final block may be < AES_BLOCK_SIZE, copy only nbytes */ - if (nbytes) { + if (!ret && nbytes) { memset(buf, 0, AES_BLOCK_SIZE); memcpy(buf, walk.src.virt.addr, nbytes); cpacf_kmctr(sctx->fc, sctx->key, buf, buf, -- 2.43.0