From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C9AD9488757; Thu, 13 Aug 2026 15:54:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786636461; cv=none; b=JG82mTGzA/EZtE9bE/JoslHgnVaV8olKjXRTmsKFB1BfJr1hXuElWpcgN/V0C6VD1JBpc/HAiHAUmotG4b4vnzIsQT6NpAbqMpo8nJOFbLJ3jAsl1gcketyNhUDoYq/eNa9VC4q7e1AN5WNbSQjE7VXkTWAeiXeil+Rkas12iHs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786636461; c=relaxed/simple; bh=TnhvjgQ+Napyf0PkgUQSG8OwkfMCu8KVyYlywY/C8GQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=O+V/xLDcxjgxz6X37r3Wd9tEwl4yMOZvm01bPAwtSv29tqtpFq6KbX2hVCtBtztP8JSsbdSHUbp3X3Qx36Umc9Xxfc2XD+Ur2VBjnROmgUdmwMUjaCoT+jqThQwrz2pEM/Jt0HnHijC1rxLeEBFf9RPvgL7A2/pd2czmRP3kfbE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=KkvpZVPD; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="KkvpZVPD" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67DFWcj12736704; Thu, 13 Aug 2026 15:54:11 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=OZ11EtV2mZPb2QIVq 17a/epK2LrZ4cxZ64YassYOTyY=; b=KkvpZVPD891b0nvz2zMXYsYTZIedSNlxT GBnUaWLFNUjR0JIsGnAS/kz5J8yfyqJnOLb74KneDYOWz9MG4Gam+vH9Y6I8TrN4 WQD+DdAiZYDEW1b5JG846v+2GUyGz+RTkrAXSRQeUBy64boRRDb8pnWTeA9woFf5 NZZa5ul2iGqFJCwQ3p12t7Rny/IBrf9nOdXoPSlDIGhR41ywwb6VTAXKRHs1aVjz yEATtUdu15UzBzElPqsaSD6BZYx/AjgUyImJm4GU2EmcZLPzel7IWq4mAsB0hN2S h3QvVxdteifoEF1nDo9fiFwhm1yIiF7MtQnskkWW0aP+BQfwOQ7mw== Received: from ppma11.dal12v.mail.ibm.com (db.9e.1632.ip4.static.sl-reverse.com [50.22.158.219]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fwvma0rxb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 13 Aug 2026 15:54:11 +0000 (GMT) Received: from pps.filterd (ppma11.dal12v.mail.ibm.com [127.0.0.1]) by ppma11.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 67DFfeS8014496; Thu, 13 Aug 2026 15:54:10 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma11.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fxhfybdj3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 13 Aug 2026 15:54:10 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 67DFs7pI29164022 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 13 Aug 2026 15:54:07 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 29FFC20040; Thu, 13 Aug 2026 15:54:07 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 034792004B; Thu, 13 Aug 2026 15:54:07 +0000 (GMT) Received: from funtu2.ibm.com (unknown [9.111.193.32]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 13 Aug 2026 15:54:06 +0000 (GMT) From: Harald Freudenberger To: dengler@linux.ibm.com, fcallies@linux.ibm.com, ifranzki@linux.ibm.com Cc: freude@linux.ibm.com, linux-s390@vger.kernel.org, Heiko Carstens , Vasily Gorbik , Alexander Gordeev , linux-crypto@vger.kernel.org Subject: [PATCH v3 1/3] s390/crypto: Fix skcipher_walk return code handling in aes_s390 Date: Thu, 13 Aug 2026 17:54:04 +0200 Message-ID: <20260813155406.50051-2-freude@linux.ibm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260813155406.50051-1-freude@linux.ibm.com> References: <20260813155406.50051-1-freude@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-s390@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEzMDExMSBTYWx0ZWRfXwaiaBhLFVbSL L0gl4rdqs6u/G6b2XIutF8huWyv/6zD6xjGhtkeEXEIldcmhkt8b9DsvM0rsJIbA6vkUI8GVk/K ZEOa01CZmllen6SNt86U3uHb3hQr8Xe9pHfYjMDny2wuul5yATNG0hyBO8h/7H/QzC3/Pth2z5b 6BUGZe64qAzHklfWFMLkjcgbOkHKF2u3IVaP72mLAvpW25FwWaqphagV1dkGxR0ulXNx7qP+vFC SzwYh0uREtXSoZoF4OUMToOxINxO6/xxLuIyZ4/FReJTF4wrWeKhWV7TgHHgufqs+X4ZckR8AwL zCatly6vyyEOGTcS9vgVFWMssy1JYW8+x0o3YUu5dHwUrfpJNP3U+YwPTgZUYAhhAg25xmlmqD5 jLxWSuoYREA/SYgKeP0aeOAvuoOpS/DRFLyx3quBLa7qN8c0jcQoec1pntS3Ma+uSgQozBRhsoc 6OKhov5s23L3nRIEokg== X-Proofpoint-ORIG-GUID: dT_vrjQ-NtYBHZAaku9U_NM6H0jCAz3C X-Proofpoint-Spam-Info: AW1haW4tMjYwODEzMDExMSBTYWx0ZWRfX2ko0nFp/EiMv JZ34oyPrqwPgw1CGiHSM3NwhTfZDYK5FfZFy5qxEGGp5QSygB2oE2vuiTSByvA1W0scy+HnGOMi YjnwybpR0JeYriqHXD0V2lm6oztIje4= X-Authority-Analysis: v=2.4 cv=IfK3n2qa c=1 sm=1 tr=0 ts=6a7de8a3 cx=c_pps a=aDMHemPKRhS1OARIsFnwRA==:117 a=aDMHemPKRhS1OARIsFnwRA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=VwQbUJbxAAAA:8 a=CBD_y4w3mMu2BuU9sPoA:9 X-Proofpoint-GUID: dT_vrjQ-NtYBHZAaku9U_NM6H0jCAz3C X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-13_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 priorityscore=1501 impostorscore=0 bulkscore=0 clxscore=1015 lowpriorityscore=0 adultscore=0 malwarescore=0 spamscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608130111 The return codes from skcipher_walk_virt() were not properly checked before entering the processing loops in ecb_aes_crypt() and ctr_aes_crypt(). If skcipher_walk_virt() fails, the walk structure may be in an undefined state, and attempting to process data could lead to incorrect behavior or accessing uninitialized memory. Add proper return code checking to ensure correct handling of the walk initialization and walk advance and eventually return to the caller with that return code. Fixes: 7988fb2c03c8 ("crypto: s390/aes - convert to skcipher API") Signed-off-by: Harald Freudenberger Cc: stable@vger.kernel.org # 5.5+ --- arch/s390/crypto/aes_s390.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/arch/s390/crypto/aes_s390.c b/arch/s390/crypto/aes_s390.c index 62edc66d5478..366ce22d3623 100644 --- a/arch/s390/crypto/aes_s390.c +++ b/arch/s390/crypto/aes_s390.c @@ -129,7 +129,7 @@ static int ecb_aes_crypt(struct skcipher_request *req, unsigned long modifier) return fallback_skcipher_crypt(sctx, req, modifier); ret = skcipher_walk_virt(&walk, req, false); - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_km(sctx->fc | modifier, sctx->key, @@ -233,7 +233,7 @@ static int cbc_aes_crypt(struct skcipher_request *req, unsigned long modifier) return ret; memcpy(param.iv, walk.iv, AES_BLOCK_SIZE); memcpy(param.key, sctx->key, sctx->key_len); - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_kmc(sctx->fc | modifier, ¶m, @@ -359,7 +359,7 @@ static int xts_aes_crypt(struct skcipher_request *req, unsigned long modifier) memcpy(xts_param.key + offset, xts_ctx->key, xts_ctx->key_len); memcpy(xts_param.init, pcc_param.xts, 16); - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_km(xts_ctx->fc | modifier, xts_param.key + offset, @@ -487,7 +487,7 @@ static int fullxts_aes_crypt(struct skcipher_request *req, unsigned long modifi memcpy(fxts_param.tweak, req->iv, AES_BLOCK_SIZE); fxts_param.nap[0] = 0x01; /* initial alpha power (1, little-endian) */ - while ((nbytes = walk.nbytes) != 0) { + while (!ret && ((nbytes = walk.nbytes) != 0)) { /* only use complete blocks */ n = nbytes & ~(AES_BLOCK_SIZE - 1); cpacf_km(xts_ctx->fc | modifier, fxts_param.key + offset, @@ -577,7 +577,7 @@ static int ctr_aes_crypt(struct skcipher_request *req) locked = mutex_trylock(&ctrblk_lock); ret = skcipher_walk_virt(&walk, req, false); - while ((nbytes = walk.nbytes) >= AES_BLOCK_SIZE) { + while (!ret && ((nbytes = walk.nbytes) >= AES_BLOCK_SIZE)) { n = AES_BLOCK_SIZE; if (nbytes >= 2*AES_BLOCK_SIZE && locked) @@ -596,7 +596,7 @@ static int ctr_aes_crypt(struct skcipher_request *req) /* * final block may be < AES_BLOCK_SIZE, copy only nbytes */ - if (nbytes) { + if (!ret && nbytes) { memset(buf, 0, AES_BLOCK_SIZE); memcpy(buf, walk.src.virt.addr, nbytes); cpacf_kmctr(sctx->fc, sctx->key, buf, buf, -- 2.43.0