All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] crypto: inside-secure - Zeroize temporary arrays on stack with sensitive data
@ 2026-08-14  8:36 Thomas Huth
  0 siblings, 0 replies; only message in thread
From: Thomas Huth @ 2026-08-14  8:36 UTC (permalink / raw)
  To: Antoine Tenart, Herbert Xu, David S. Miller; +Cc: linux-crypto, linux-kernel

This issue has been found by the Sashiko bot while reviewing another
patch: key_tmp[] in safexcel_xcbcmac_setkey() and consts[] / _const[]
in safexcel_cmac_setkey() contain crypto key material that should not
get exposed to the outside once the function is done. Scrub the arrays
with memzero_explicit() to avoid that the data could leak via the stack.

Signed-off-by: Thomas Huth <thuth@redhat.com>
---
 drivers/crypto/inside-secure/safexcel_hash.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/crypto/inside-secure/safexcel_hash.c b/drivers/crypto/inside-secure/safexcel_hash.c
index 3402e570d045c..1ae6fbec31298 100644
--- a/drivers/crypto/inside-secure/safexcel_hash.c
+++ b/drivers/crypto/inside-secure/safexcel_hash.c
@@ -1993,6 +1993,7 @@ static int safexcel_xcbcmac_setkey(struct crypto_ahash *tfm, const u8 *key,
 	ret = aes_prepareenckey(ctx->aes,
 				(u8 *)key_tmp + 2 * AES_BLOCK_SIZE,
 				AES_MIN_KEY_SIZE);
+	memzero_explicit(key_tmp, sizeof(key_tmp));
 	if (ret)
 		return ret;
 
@@ -2104,6 +2105,9 @@ static int safexcel_cmac_setkey(struct crypto_ahash *tfm, const u8 *key,
 	}
 	ctx->cbcmac = false;
 
+
+	memzero_explicit(consts, sizeof(consts));
+	memzero_explicit(_const, sizeof(_const));
 	return 0;
 }
 
-- 
2.55.0


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-14  8:37 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-14  8:36 [PATCH] crypto: inside-secure - Zeroize temporary arrays on stack with sensitive data Thomas Huth

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.