From: Thomas Huth <thuth@redhat.com>
To: Eric Biggers <ebiggers@kernel.org>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
"Jason A. Donenfeld" <Jason@zx2c4.com>,
Ard Biesheuvel <ardb@kernel.org>
Cc: linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>
Subject: [PATCH v2 02/13] lib/crypto: aes-xts: Provide function for zeroizing aes_xts_key
Date: Wed, 9 Sep 2026 13:54:38 +0200 [thread overview]
Message-ID: <20260909115455.157093-3-thuth@redhat.com> (raw)
In-Reply-To: <20260909115455.157093-1-thuth@redhat.com>
In certain cases crypto code functions need to zeroize their local
aes_xts_key structures after use to avoid leaking sensitive material.
Provide an aes_xts_zeroize_key() helper function that e.g. can be
used with __cleanup() to automatically zeroize the struct when it
goes out of scope.
While we're at it, replace the related memzero_explicit() call in
lib/crypto/aes.c with a call to the new helper function.
Signed-off-by: Thomas Huth <thuth@redhat.com>
---
include/crypto/aes-xts.h | 13 +++++++++++--
lib/crypto/aes.c | 2 +-
2 files changed, 12 insertions(+), 3 deletions(-)
diff --git a/include/crypto/aes-xts.h b/include/crypto/aes-xts.h
index b9e828265e58a..3a52e1cf40b57 100644
--- a/include/crypto/aes-xts.h
+++ b/include/crypto/aes-xts.h
@@ -22,6 +22,15 @@ struct aes_xts_key {
struct aes_enckey tweak_key;
};
+/**
+ * aes_xts_zeroize_key() - Zeroize an aes_xts_key structure
+ * @key: The aes_xts_key to zeroize
+ */
+static inline void aes_xts_zeroize_key(struct aes_xts_key *key)
+{
+ memzero_explicit(key, sizeof(*key));
+}
+
/**
* aes_xts_preparekey() - Prepare a key for AES-XTS encryption and decryption
* @key: (output) The key structure to initialize
@@ -30,8 +39,8 @@ struct aes_xts_key {
* @flags: Optional flag XTS_FORBID_WEAK_KEYS to forbid keys whose two halves
* are the same.
*
- * Users should use memzero_explicit() to zeroize the key struct at the end of
- * its lifetime. (But if this function fails, zeroization is unnecessary.)
+ * Users should use aes_xts_zeroize_key() to zeroize the key struct at the end
+ * of its lifetime. (But if this function fails, zeroization is unnecessary.)
*
* Context: Any context.
* Return:
diff --git a/lib/crypto/aes.c b/lib/crypto/aes.c
index 07c1d912ac365..34ef5deca0a79 100644
--- a/lib/crypto/aes.c
+++ b/lib/crypto/aes.c
@@ -1223,7 +1223,7 @@ int aes_xts_preparekey(struct aes_xts_key *key, const u8 *in_key,
return 0;
out_zeroize:
- memzero_explicit(key, sizeof(*key));
+ aes_xts_zeroize_key(key);
return err;
}
EXPORT_SYMBOL_GPL(aes_xts_preparekey);
--
2.55.0
next prev parent reply other threads:[~2026-09-09 11:55 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 11:54 [PATCH v2 00/13] libcrypto: Provide more __cleanup functions for zeroizing data Thomas Huth
2026-09-09 11:54 ` [PATCH v2 01/13] lib/crypto: aes: Provide functions for zeroizing aes_key and aes_enckey Thomas Huth
2026-09-09 11:54 ` Thomas Huth [this message]
2026-09-09 11:54 ` [PATCH v2 03/13] lib/crypto: aes-gcm: Provide functions for zeroizing aes_gcm* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 04/13] lib/crypto: aes-ccm: Provide functions for zeroizing aes_ccm* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 05/13] lib/crypto: md5: Provide a function for zeroizing hmac_md5 structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 06/13] lib/crypto: sm3: Provide a function for zeroizing the sm3_ctx structure Thomas Huth
2026-09-09 11:54 ` [PATCH v2 07/13] lib/crypto: blake2: Provide functions for zeroizing blake2*_ctx structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 08/13] lib/crypto: sha1: Provide functions for zeroizing hmac_sha1 structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 09/13] security: keys: trusted: always clear the hmac_sha1_ctx before returning Thomas Huth
2026-09-09 11:54 ` [PATCH v2 10/13] x86/purgatory: Compile purgatory.c with -D__NO_FORTIFY Thomas Huth
2026-09-09 11:54 ` [PATCH v2 11/13] lib/crypto: sha2: Provide functions for zeroizing SHA2 hmac_sha* structures Thomas Huth
2026-09-09 11:54 ` [PATCH v2 12/13] smb: client: Use hmac_sha256_zeroize_ctx function to clear hmac_sha256_ctx Thomas Huth
2026-09-09 11:54 ` [PATCH v2 13/13] lib/crypto: Add documentation about zeroization of key and context data Thomas Huth
2026-09-09 13:22 ` Jonathan Corbet
2026-09-10 9:09 ` Thomas Huth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909115455.157093-3-thuth@redhat.com \
--to=thuth@redhat.com \
--cc=Jason@zx2c4.com \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.