linux-security-module.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] KEYS: encrypted: fix key instantiation with user-provided data
@ 2022-09-16  5:45 Nikolaus Voss
  2022-09-20  5:06 ` Jarkko Sakkinen
  2022-09-20 14:43 ` Mimi Zohar
  0 siblings, 2 replies; 13+ messages in thread
From: Nikolaus Voss @ 2022-09-16  5:45 UTC (permalink / raw)
  To: Mimi Zohar, David Howells, Jarkko Sakkinen, James Morris,
	Serge E. Hallyn
  Cc: linux-integrity, keyrings, linux-security-module, linux-kernel

Commit cd3bc044af48 ("KEYS: encrypted: Instantiate key with user-provided
decrypted data") added key instantiation with user provided decrypted data.
The user data is hex-ascii-encoded but was just memcpy'ed to the binary buffer.
Fix this to use hex2bin instead.

Fixes: cd3bc044af48 ("KEYS: encrypted: Instantiate key with user-provided decrypted data")
Cc: stable <stable@kernel.org>
Signed-off-by: Nikolaus Voss <nikolaus.voss@haag-streit.com>
---
 security/keys/encrypted-keys/encrypted.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/security/keys/encrypted-keys/encrypted.c b/security/keys/encrypted-keys/encrypted.c
index e05cfc2e49ae..1e313982af02 100644
--- a/security/keys/encrypted-keys/encrypted.c
+++ b/security/keys/encrypted-keys/encrypted.c
@@ -627,7 +627,7 @@ static struct encrypted_key_payload *encrypted_key_alloc(struct key *key,
 			pr_err("encrypted key: instantiation of keys using provided decrypted data is disabled since CONFIG_USER_DECRYPTED_DATA is set to false\n");
 			return ERR_PTR(-EINVAL);
 		}
-		if (strlen(decrypted_data) != decrypted_datalen) {
+		if (strlen(decrypted_data) != decrypted_datalen * 2) {
 			pr_err("encrypted key: decrypted data provided does not match decrypted data length provided\n");
 			return ERR_PTR(-EINVAL);
 		}
@@ -791,8 +791,8 @@ static int encrypted_init(struct encrypted_key_payload *epayload,
 		ret = encrypted_key_decrypt(epayload, format, hex_encoded_iv);
 	} else if (decrypted_data) {
 		get_random_bytes(epayload->iv, ivsize);
-		memcpy(epayload->decrypted_data, decrypted_data,
-				   epayload->decrypted_datalen);
+		ret = hex2bin(epayload->decrypted_data, decrypted_data,
+			      epayload->decrypted_datalen);
 	} else {
 		get_random_bytes(epayload->iv, ivsize);
 		get_random_bytes(epayload->decrypted_data, epayload->decrypted_datalen);
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2022-10-05 10:04 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-09-16  5:45 [PATCH] KEYS: encrypted: fix key instantiation with user-provided data Nikolaus Voss
2022-09-20  5:06 ` Jarkko Sakkinen
2022-09-20  7:58   ` Nikolaus Voss
2022-09-21 17:51     ` Jarkko Sakkinen
2022-09-28 13:03       ` Nikolaus Voss
2022-09-20 14:43 ` Mimi Zohar
2022-09-20 16:23   ` Nikolaus Voss
2022-09-20 22:53     ` Mimi Zohar
2022-09-21  7:24       ` Nikolaus Voss
2022-09-21 12:49         ` Mimi Zohar
2022-09-28 12:08           ` Nikolaus Voss
2022-09-28 16:33             ` Mimi Zohar
2022-10-05 10:04               ` Nikolaus Voss

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).