Linux s390 Architecture development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Harald Freudenberger" <freude@linux.ibm.com>
Cc: linux-s390@vger.kernel.org,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	"Heiko Carstens" <hca@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>
Subject: Re: [PATCH v5 2/3] s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm
Date: Mon, 31 Aug 2026 09:05:22 +0000	[thread overview]
Message-ID: <20260831090523.230C11F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831083735.3625-4-freude@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The temporary stack buffer `buf` in `ctr_paes_do_crypt()` is not explicitly scrubbed before the function returns, leaving sensitive plaintext and/or ciphertext data exposed on the kernel stack. This is identical to the issue fixed in `ctr_aes_crypt()` by this patchset, which missed the Protected AES counterpart implementation.
--

commit 5028b97eb1d91a81a384b0480662106643fa02f9
Author: Harald Freudenberger <freude@linux.ibm.com>

s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm

This commit fixes missing explicit scrubs of temporary stack buffers and
CPACF parameter blocks in the s390 AES CTR and GCM implementations. It
ensures sensitive data is cleared before the functions return.

> diff --git a/arch/s390/crypto/aes_s390.c b/arch/s390/crypto/aes_s390.c
> index 366ce22d36237..10561aa687c78 100644
> --- a/arch/s390/crypto/aes_s390.c
> +++ b/arch/s390/crypto/aes_s390.c
> @@ -604,6 +604,7 @@ static int ctr_aes_crypt(struct skcipher_request *req)
>  		memcpy(walk.dst.virt.addr, buf, nbytes);
>  		crypto_inc(walk.iv, AES_BLOCK_SIZE);
>  		ret = skcipher_walk_done(&walk, 0);
> +		memzero_explicit(buf, sizeof(buf));

[Severity: High]
This is a pre-existing issue, but does the Protected AES counterpart need
this identical fix?

Looking at ctr_paes_do_crypt() in arch/s390/crypto/paes_s390.c, there is a
similar temporary stack buffer used for partial block processing that does
not appear to be scrubbed before returning:

arch/s390/crypto/paes_s390.c:ctr_paes_do_crypt() {
    ...
		memcpy(walk->dst.virt.addr, buf, nbytes);
		crypto_inc(walk->iv, AES_BLOCK_SIZE);
		rc = skcipher_walk_done(walk, 0);
	}

out:
	pr_debug("rc=%d\n", rc);
	return rc;
}

Can executing a cryptographic operation in Protected AES CTR mode with a data
length that is not a multiple of AES_BLOCK_SIZE expose sensitive plaintext or
ciphertext bytes on the kernel stack when this buffer goes out of scope?

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260831083735.3625-1-freude@linux.ibm.com?part=2

  reply	other threads:[~2026-08-31  9:05 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31  8:37 [PATCH v5 0/3] Fixes and rework for aes_s390 Harald Freudenberger
2026-08-31  8:37 ` Harald Freudenberger
2026-08-31  8:37 ` [PATCH v5 1/3] s390/crypto: Fix skcipher_walk return code handling in aes_s390 Harald Freudenberger
2026-08-31  8:49   ` sashiko-bot
2026-08-31  8:37 ` [PATCH v5 2/3] s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm Harald Freudenberger
2026-08-31  9:05   ` sashiko-bot [this message]
2026-08-31  8:37 ` [PATCH v5 3/3] s390/crypto: Fix use of mutex in atomic context Harald Freudenberger
2026-08-31  9:10   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831090523.230C11F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=freude@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox