All of lore.kernel.org
 help / color / mirror / Atom feed
From: Holger Dengler <dengler@linux.ibm.com>
To: Harald Freudenberger <freude@linux.ibm.com>
Cc: fcallies@linux.ibm.com, ifranzki@linux.ibm.com,
	linux-s390@vger.kernel.org, Heiko Carstens <hca@linux.ibm.com>,
	Vasily Gorbik <gor@linux.ibm.com>,
	Alexander Gordeev <agordeev@linux.ibm.com>,
	linux-crypto@vger.kernel.org
Subject: Re: [PATCH v3 2/6] s390/crypto: Fix missing scrub of temp buffers with PAES algorithm
Date: Tue, 18 Aug 2026 09:32:07 +0200	[thread overview]
Message-ID: <aa6f0aee-2ecb-4426-b281-698ccf29e890@linux.ibm.com> (raw)
In-Reply-To: <20260817141654.77940-3-freude@linux.ibm.com>

On 8/17/26 16:16, Harald Freudenberger wrote:
> In function ctr_paes_do_crypt() there is a buffer used to process
> remaining bytes < AES_BLOCK_SIZE. This buffer was not scrubbed and
> thus could lead to expose of unwanted data. Rework the code to
> explicitly scrub the buffer at the end of the function to avoid
> exposure of maybe sensitive data.
> 
> In function __xts_2keys_prep_param() change the existing scrub to
> clean the whole param block instead of just the key field.
> 
> Fixes: 6cd87cb5ef6c ("s390/crypto: Rework protected key AES for true asynch support")
> Signed-off-by: Harald Freudenberger <freude@linux.ibm.com>
> Cc: stable@vger.kernel.org # 6.16+

Reviewed-by: Holger Dengler <dengler@linux.ibm.com>

-- 
Mit freundlichen Grüßen / Kind regards
Holger Dengler


  parent reply	other threads:[~2026-08-18  7:32 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-17 14:16 [PATCH v3 0/6] Fixes and rework for paes_s390 Harald Freudenberger
2026-08-17 14:16 ` [PATCH v3 1/6] s390/crypto: Fix return code handling at skcipher_walk_done in PAES algorithms Harald Freudenberger
2026-08-17 14:22   ` sashiko-bot
2026-08-18  7:11   ` Holger Dengler
2026-08-17 14:16 ` [PATCH v3 2/6] s390/crypto: Fix missing scrub of temp buffers with PAES algorithm Harald Freudenberger
2026-08-17 14:23   ` sashiko-bot
2026-08-18  7:32   ` Holger Dengler [this message]
2026-08-17 14:16 ` [PATCH v3 3/6] s390/crypto: Fix use of mutex in atomic context in PAES Harald Freudenberger
2026-08-17 14:26   ` sashiko-bot
2026-08-18  7:49   ` Holger Dengler
2026-08-17 14:16 ` [PATCH v3 4/6] s390/crypto: Fix missing cra_flags in paes_s390 Harald Freudenberger
2026-08-17 14:22   ` sashiko-bot
2026-08-18  7:54   ` Holger Dengler
2026-08-17 14:16 ` [PATCH v3 5/6] s390/crypto: Fix handling of EBUSY in PAES when req is pushed to crypto engine Harald Freudenberger
2026-08-17 14:27   ` sashiko-bot
2026-08-17 14:16 ` [PATCH v3 6/6] s390/crypto: Fix handling of EBUSY in PHMAC " Harald Freudenberger
2026-08-17 14:35   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aa6f0aee-2ecb-4426-b281-698ccf29e890@linux.ibm.com \
    --to=dengler@linux.ibm.com \
    --cc=agordeev@linux.ibm.com \
    --cc=fcallies@linux.ibm.com \
    --cc=freude@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=ifranzki@linux.ibm.com \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.