Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Alex Ousherovitch" <aousherovitch@rambus.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v5 12/19] crypto: cmh - add RSA akcipher
Date: Thu, 17 Sep 2026 23:10:39 +0000	[thread overview]
Message-ID: <20260917231039.E0F0D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917225929.2494111-13-aousherovitch@rambus.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] crypto: cmh: partial tfm state corruption on set_pub_key failure
--

commit 245d9a370fc37764e90c38f7f7cb69490074e21e
Author: Alex Ousherovitch <aousherovitch@rambus.com>

crypto: cmh - add RSA akcipher

This commit registers the RSA akcipher algorithm using the CMH PKE core,
supporting encryption, decryption, signing, and verification operations
for multiple key sizes.

> diff --git a/drivers/crypto/cmh/cmh_pke_rsa.c b/drivers/crypto/cmh/cmh_pke_rsa.c
> new file mode 100644
> index 0000000000000..251ae8275865d
> --- /dev/null
> +++ b/drivers/crypto/cmh/cmh_pke_rsa.c
[ ... ]
> +static int cmh_rsa_set_pub_key(struct crypto_akcipher *tfm,
> +			       const void *key, unsigned int keylen)
> +{
> +	struct cmh_rsa_tfm_ctx *ctx = cmh_rsa_ctx(tfm);
> +	struct rsa_key rsa = {};
> +	u32 bits;
> +	int ret;
> +
> +	/*
> +	 * Re-keying: release any private-key state (and its persistent DMA
> +	 * mapping) left by a prior set_priv_key so it is not leaked until
> +	 * exit_tfm and cannot be mistaken for the new public key.
> +	 */
> +	cmh_key_destroy(&ctx->key);
> +
> +	ret = rsa_parse_pub_key(&rsa, key, keylen);
> +	if (ret)
> +		return ret;

[Severity: Medium]
Does this leave the transform in a partially corrupted state if parsing fails?

If cmh_rsa_set_pub_key() is called after a key pair has already been
configured, the private key is destroyed early. If rsa_parse_pub_key() then
fails, the function returns without updating or clearing the existing public
key.

Userspace could potentially trigger this via the AF_ALG socket interface by
passing malformed key material. This would leave the transform in an
inconsistent state where encryption still works using the old public key, but
decryption fails.

Should the old private key be preserved until the new public key is fully
validated, or should the entire transform state be wiped on error?

The same pattern also appears in cmh_rsa_set_priv_key() where the old private
key could be left active while the public key is freed on a failure during
key material setup.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917225929.2494111-1-aousherovitch@rambus.com?part=12

  reply	other threads:[~2026-09-17 23:10 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 22:59 [PATCH v5 00/19] crypto: cmh - add Rambus CryptoManager Hub driver Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 01/19] dt-bindings: crypto: add Rambus CryptoManager Hub Alex Ousherovitch
2026-09-17 23:08   ` sashiko-bot
2026-09-28 18:18   ` Rob Herring
2026-10-03  0:01     ` Ousherovitch, Alex
2026-09-17 22:59 ` [PATCH v5 02/19] crypto: cmh - add core platform driver Alex Ousherovitch
2026-09-17 23:17   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 03/19] crypto: cmh - add key provisioning and management Alex Ousherovitch
2026-09-17 23:15   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 04/19] crypto: cmh - add SHA-2/SHA-3/SHAKE ahash Alex Ousherovitch
2026-09-17 23:11   ` sashiko-bot
2026-09-23  5:47   ` Herbert Xu
2026-09-23 20:50     ` Ousherovitch, Alex
2026-09-28  5:17       ` Herbert Xu
2026-10-05 17:04         ` Ousherovitch, Alex
2026-10-05 22:31           ` Ousherovitch, Alex
2026-10-08  8:20           ` Herbert Xu
2026-10-08 18:19             ` Ousherovitch, Alex
2026-09-17 22:59 ` [PATCH v5 05/19] crypto: cmh - add HMAC ahash Alex Ousherovitch
2026-09-17 23:14   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 06/19] crypto: cmh - add CSHAKE/KMAC ahash Alex Ousherovitch
2026-09-17 23:16   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 07/19] crypto: cmh - add SM3 ahash Alex Ousherovitch
2026-09-17 23:12   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 08/19] crypto: cmh - add AES skcipher/aead/cmac Alex Ousherovitch
2026-09-17 23:11   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 09/19] crypto: cmh - add SM4 skcipher/aead/cmac/xcbc Alex Ousherovitch
2026-09-17 23:10   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 10/19] crypto: cmh - add ChaCha20-Poly1305 Alex Ousherovitch
2026-09-17 23:11   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 11/19] crypto: cmh - add DRBG hwrng Alex Ousherovitch
2026-09-17 23:14   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 12/19] crypto: cmh - add RSA akcipher Alex Ousherovitch
2026-09-17 23:10   ` sashiko-bot [this message]
2026-09-17 22:59 ` [PATCH v5 13/19] crypto: cmh - add ECDSA/SM2 sig Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 14/19] crypto: cmh - add ECDH/X25519 kpp Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 15/19] crypto: cmh - add ML-KEM/ML-DSA (QSE) Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 16/19] crypto: cmh - add SLH-DSA/LMS/XMSS (HCQ) Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 17/19] Documentation: ioctl: add CMH ioctl documentation and register 'J' Alex Ousherovitch
2026-09-17 23:17   ` sashiko-bot
2026-09-17 22:59 ` [PATCH v5 18/19] selftests: crypto: cmh - add kselftest for management ioctl Alex Ousherovitch
2026-09-17 22:59 ` [PATCH v5 19/19] MAINTAINERS: add Rambus CryptoManager Hub (CMH) Alex Ousherovitch
2026-09-23  5:48 ` [PATCH v5 00/19] crypto: cmh - add Rambus CryptoManager Hub driver Herbert Xu
2026-09-23 17:42   ` Ousherovitch, Alex

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917231039.E0F0D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=aousherovitch@rambus.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox