From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F23644AB8F for ; Wed, 5 Aug 2026 11:58:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931084; cv=none; b=cRdM74OcKBpLqImO0TYyagPcZe2sryhgt/4aEEBNl19u+v2hsCzTrDcLreo/aPxZ0DB4wHDsCJQZuGnaMFcbg/AL814FTyiwl4Nri9cuIUfW76fvQyeZ3ooLCthTQpVMNUkPHpHXB2HTlH+WofMSSY/4lJkxl+jPpfoqM6yF8eo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931084; c=relaxed/simple; bh=yw/JPU3AhK0bU1PIxC6NpN8/dO32Q22HNdfqE+3cj18=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=F9+emFxkDMPJyZqU/h3DY4OjI6xBfpcTqDEbV2fjpghcGodPAce3wunKSnugytrb8gzDGOVwmG1LJS+f5zQfoHNrFMX59vV+6hI7kb4iSnfhToD+MnDYW0QIY7Dm3EIP5xnmV7wdWkK36qMdb6vPfWFFnlGu9076OwGTR5Y5nls= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=aBqFGbXP; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="aBqFGbXP" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931082; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ULLBSh1RmnUuu3Ug3555qqjX9ogDob1JcFCmK/FvMFs=; b=aBqFGbXPGJ3oKT0ca4mzRHM7AvYNnziarRxL3hoAY+yQmW1A5tiFzLmLC152evpMLkACM2 aZd/6vKSwkdoP7GePcQfiaJQvvkzIeBx2T1LJDJs6dUSeyNfQ6NMfMfRWbzWS8NI/hj+ee gOcHsP8YS4Z92RxrRgGLfonEvzvtNao= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-55-IeDW5EGaNjCeAGC6TU_BEQ-1; Wed, 05 Aug 2026 07:57:57 -0400 X-MC-Unique: IeDW5EGaNjCeAGC6TU_BEQ-1 X-Mimecast-MFC-AGG-ID: IeDW5EGaNjCeAGC6TU_BEQ_1785931076 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id CF9A119560B4; Wed, 5 Aug 2026 11:57:55 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1535730001A2; Wed, 5 Aug 2026 11:57:53 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org Cc: Eric Biggers Subject: [PATCH v3 01/10] crypto: Provide a wrapper function for zeroizing crypto_aes_ctx Date: Wed, 5 Aug 2026 13:57:39 +0200 Message-ID: <20260805115749.392672-2-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Several crypto drivers need to zeroize their local crypto_aes_ctx structures after use to avoid leaking key material on the stack. Currently some call sites do this with their own memzero_explicit() call, which is error-prone since it is easy to miss a return path (what already happened in a driver). Some other call sites miss to clear crypto_aes_ctx completely. Provide an aes_zeroize_ctx() helper that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Acked-by: Eric Biggers Signed-off-by: Thomas Huth --- include/crypto/aes.h | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/include/crypto/aes.h b/include/crypto/aes.h index 3279cfa546085..eb970b8d623f9 100644 --- a/include/crypto/aes.h +++ b/include/crypto/aes.h @@ -159,6 +159,19 @@ static inline int aes_check_keylen(size_t keylen) int aes_expandkey(struct crypto_aes_ctx *ctx, const u8 *in_key, unsigned int key_len); =20 +/** + * aes_zeroize_ctx - Clear a crypto_aes_ctx structure + * @ctx: The location of the context that should be zeroized + * + * Explicitly fills the crypto_aes_ctx with zeroes. This should be done + * once the context is not required anymore to avoid that its contents + * are leaked on the stack or heap. + */ +static inline void aes_zeroize_ctx(struct crypto_aes_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /* * The following functions are temporarily exported for use by the AES mode * implementations in arch/$(SRCARCH)/crypto/. These exports will go away= when --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9EFC944E65A for ; Wed, 5 Aug 2026 11:58:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931106; cv=none; b=ud3KdKkCR0GEh+8PSEZRyXknM45OV2ImtD72LP1dUNrX6KcGX9fL7No8D9GaIAqzrGQcsEy973Z5zWSSsXf4TkriToNQ8CKGU3QVDazrH4jtpr1KBYlWEsM3whcrXJsd9JsLB/6m6yFoVTuqtsYC3Eb0/k3v+qhlaFfpW6obdvo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931106; c=relaxed/simple; bh=WVt0qQ4+1eH0aK8H3LOcQUCnNbq+Qzdzr1yi2CdD+9o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=juEDs3QqmVN8SLkD927Ik/gbogufZO1hvUse1jutEtqiuFVcPVUczzXSp6UlrFZhW3CIlqjYWuF9TtPnMj0m2ZFHNUBqhH42XvwYDWu4fujXT0N+jvsjh/pzTMZDGQuot9e33h7DtcmnP9gQViHwvHV5lJupNxsQNT5KoEZ5CvQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=WShDt9ER; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="WShDt9ER" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931102; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=rFuj09l13bDJWP8ROOQNO6DWGBJe5ddETVvR3frCMgU=; b=WShDt9ER3f26womp7AMiRnwwopRRqx6ldNl2k2srK6uWh2l8WwogMlfducRdNN30t72+I/ nLF95oHVBThOTqVVKTIMGaqjjT4W912BBrbEI0cpUkG+UPOeN9gO0gTbrB6038CoFosp+7 SaVqXJW+mN8YnSvtBNf3m+48sgsAFDs= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-610-yPW5ZYxUMim58sgn2KjWOg-1; Wed, 05 Aug 2026 07:58:03 -0400 X-MC-Unique: yPW5ZYxUMim58sgn2KjWOg-1 X-Mimecast-MFC-AGG-ID: yPW5ZYxUMim58sgn2KjWOg_1785931081 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 826E4195608E; Wed, 5 Aug 2026 11:58:00 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 644DC30001A2; Wed, 5 Aug 2026 11:57:56 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Neal Liu , Joel Stanley , Andrew Jeffery , linux-aspeed@lists.ozlabs.org, linux-arm-kernel@lists.infradead.org Cc: Eric Biggers Subject: [PATCH v3 02/10] crypto: aspeed - clear the crypto_aes_ctx when done Date: Wed, 5 Aug 2026 13:57:40 +0200 Message-ID: <20260805115749.392672-3-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Declare the gen_aes_key with __cleanup(aes_zeroize_ctx) to avoid that its contents could be leaking via the stack when the function returns. And since it is only required in one branch of the if-statement there, move it to that block, too. Signed-off-by: Thomas Huth --- drivers/crypto/aspeed/aspeed-hace-crypto.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/crypto/aspeed/aspeed-hace-crypto.c b/drivers/crypto/as= peed/aspeed-hace-crypto.c index fa201dae1f81b..e7d3f611df05c 100644 --- a/drivers/crypto/aspeed/aspeed-hace-crypto.c +++ b/drivers/crypto/aspeed/aspeed-hace-crypto.c @@ -576,7 +576,6 @@ static int aspeed_aes_setkey(struct crypto_skcipher *ci= pher, const u8 *key, { struct aspeed_cipher_ctx *ctx =3D crypto_skcipher_ctx(cipher); struct aspeed_hace_dev *hace_dev =3D ctx->hace_dev; - struct crypto_aes_ctx gen_aes_key; =20 CIPHER_DBG(hace_dev, "keylen: %d bits\n", (keylen * 8)); =20 @@ -585,9 +584,9 @@ static int aspeed_aes_setkey(struct crypto_skcipher *ci= pher, const u8 *key, return -EINVAL; =20 if (ctx->hace_dev->version =3D=3D AST2500_VERSION) { + struct crypto_aes_ctx gen_aes_key __cleanup(aes_zeroize_ctx); aes_expandkey(&gen_aes_key, key, keylen); memcpy(ctx->key, gen_aes_key.key_enc, AES_MAX_KEYLENGTH); - } else { memcpy(ctx->key, key, keylen); } --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9761E44AB74 for ; Wed, 5 Aug 2026 11:58:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931096; cv=none; b=IrpnEw3YZuhgFGpUR8xdT781FnkAgK+6FwqkS/t6WjPgZuP95dGO+FABTj3/XHXwEoVDaWF/E7ekAM+BSzpZeRLHOojUd+PAEnMsfWRHFn3hxQi9TE/QQm8D2zNjr7qTkkZgGa6qEAHw33Q9IxJRvANjBMXhsIVatMojy8LJF1s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931096; c=relaxed/simple; bh=vzZOFKBz/vS1L4OiBZo1G1l389pu1nVzeo0UGyLy+sw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HehJ/ZPYwSJ9IR/1r+QNhkkzzZqEyP7BfOZoxeNaoVz5ib9fRG1tFhfvo0SAQ0Ux1KK+EmBdmybKytO0R2Q8tBfnTp9PlzyzaWMF9ym4PdWnSTI7kcTv4hiyZiU0jJHjpGDmfYccUsFZBMvQJeHjbO1DTa8ldfio2pPFXGHSpPI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=KAc+U9BT; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="KAc+U9BT" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931093; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=5/FP2iona05c4GGFGjhMtKYGShx3GCcZ6CaDckfTOnk=; b=KAc+U9BTQAemfQOzf0u4V42IkvjoQQtKCfoRE4o7oTWI79vuwB27lrF63TBOK4NICWH4/0 C9D+JF4SSrv518UJSEuXRpnqV/2SEglJAcA/i8K6/n1j6ic5TQ3gUaZlvd57bhBhRBluV8 9cPlVCR+Dx2qVBx6Y4+Lkn31R7iICfA= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-679--16dSFeXN4GJtlujppaAxg-1; Wed, 05 Aug 2026 07:58:05 -0400 X-MC-Unique: -16dSFeXN4GJtlujppaAxg-1 X-Mimecast-MFC-AGG-ID: -16dSFeXN4GJtlujppaAxg_1785931084 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id BA9F519560B4; Wed, 5 Aug 2026 11:58:03 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 7710230002EA; Wed, 5 Aug 2026 11:58:00 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Christian Marangi , Antoine Tenart Cc: Eric Biggers Subject: [PATCH v3 03/10] crypto: inside-secure/eip93 - clear the crypto_aes_ctx when done Date: Wed, 5 Aug 2026 13:57:41 +0200 Message-ID: <20260805115749.392672-4-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- drivers/crypto/inside-secure/eip93/eip93-aead.c | 2 +- drivers/crypto/inside-secure/eip93/eip93-cipher.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/crypto/inside-secure/eip93/eip93-aead.c b/drivers/cryp= to/inside-secure/eip93/eip93-aead.c index 2bbd0af7b0e0e..973cebef5df37 100644 --- a/drivers/crypto/inside-secure/eip93/eip93-aead.c +++ b/drivers/crypto/inside-secure/eip93/eip93-aead.c @@ -92,7 +92,7 @@ static int eip93_aead_setkey(struct crypto_aead *ctfm, co= nst u8 *key, struct crypto_tfm *tfm =3D crypto_aead_tfm(ctfm); struct eip93_crypto_ctx *ctx =3D crypto_tfm_ctx(tfm); struct crypto_authenc_keys keys; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); struct sa_record *sa_record =3D ctx->sa_record; u32 nonce =3D 0; int ret; diff --git a/drivers/crypto/inside-secure/eip93/eip93-cipher.c b/drivers/cr= ypto/inside-secure/eip93/eip93-cipher.c index 4dd7ab7503e85..7051b99ee6235 100644 --- a/drivers/crypto/inside-secure/eip93/eip93-cipher.c +++ b/drivers/crypto/inside-secure/eip93/eip93-cipher.c @@ -116,7 +116,7 @@ static int eip93_skcipher_setkey(struct crypto_skcipher= *ctfm, const u8 *key, } =20 if (flags & EIP93_ALG_AES) { - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); =20 ctx->blksize =3D AES_BLOCK_SIZE; ret =3D aes_expandkey(&aes, key, keylen); --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5DB8944D014 for ; Wed, 5 Aug 2026 11:58:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931102; cv=none; b=fJMgn8hPLe/AWl+lx+RKJ70bt/ZwrdhhnldN5VRwf2FcEBmLA/1Ri9PTOme+bMGNhjwQa6lSzFZU7lqOLU71ha9v9GTos9bhi+gJyRksbDqYLQzUZW2J/q71pUaAuDrn/GwIr4p7ID+C0mhFhhm2hKuJ6fzcVxg61nPR06AyDXg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931102; c=relaxed/simple; bh=rrHOeIvGuTbxvBxf0sD+S1Wa6q8TEDfmgAXE4+BZst4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gbeXNpnDmFyKlthYgAhHJkuhUQZkOAbh6QLIjMDevscqsHDxhgnsVViQNSj7ddVmE/ImhiSTK2MhM/J3xMc9cX3J/dNzJz+H/jjU0YtsRUbPqmPHEIpCCVRig/76lhdGKfyxRMIDW1IN/n89Nw3aMBKp9A616HflxxXeEAhsglg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=bWhpjXrG; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="bWhpjXrG" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931100; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=dFIxmKcUsq1WalhKwXv0wsQgLSJrF7IelNY2pEdEa3U=; b=bWhpjXrGGhpw8+1suG8CvjfJ6YqNc+izc4K5NM2opsRvCrFc06W6263U0x7dB2tEMtWk9j IN0xlQzlr+T/zayaWXNDcEqzMSGtlzcAW+WPotHDwYmw+ZfE/wkWMjrVhTWeaoUITeLPBx 89FUVJ+LpFRfouIIjaCF1Id3+kRjcAk= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-688-S3dhsJWwNV-vIPG2bC1I2w-1; Wed, 05 Aug 2026 07:58:07 -0400 X-MC-Unique: S3dhsJWwNV-vIPG2bC1I2w-1 X-Mimecast-MFC-AGG-ID: S3dhsJWwNV-vIPG2bC1I2w_1785931086 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 1163E19560AA; Wed, 5 Aug 2026 11:58:06 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 515F330001A2; Wed, 5 Aug 2026 11:58:04 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org Cc: Eric Biggers Subject: [PATCH v3 04/10] crypto: padlock-aes - clear the crypto_aes_ctx when done Date: Wed, 5 Aug 2026 13:57:42 +0200 Message-ID: <20260805115749.392672-5-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. And since __cleanup() (and __free()) should not be mixed with "gotos" in the same function, turn the goto statement here into a proper block of the related if-statement. Signed-off-by: Thomas Huth --- drivers/crypto/padlock-aes.c | 22 ++++++++++------------ 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/drivers/crypto/padlock-aes.c b/drivers/crypto/padlock-aes.c index 1be549a07a219..400a889e924d7 100644 --- a/drivers/crypto/padlock-aes.c +++ b/drivers/crypto/padlock-aes.c @@ -109,7 +109,7 @@ static int aes_set_key(struct crypto_tfm *tfm, const u8= *in_key, { struct aes_ctx *ctx =3D aes_ctx(tfm); const __le32 *key =3D (const __le32 *)in_key; - struct crypto_aes_ctx gen_aes; + struct crypto_aes_ctx gen_aes __cleanup(aes_zeroize_ctx); int cpu; =20 if (key_len % 8) @@ -137,20 +137,18 @@ static int aes_set_key(struct crypto_tfm *tfm, const = u8 *in_key, ctx->cword.decrypt.ksize =3D ctx->cword.encrypt.ksize; =20 /* Don't generate extended keys if the hardware can do it. */ - if (aes_hw_extkey_available(key_len)) - goto ok; + if (!aes_hw_extkey_available(key_len)) { + ctx->D =3D ctx->d_data; + ctx->cword.encrypt.keygen =3D 1; + ctx->cword.decrypt.keygen =3D 1; =20 - ctx->D =3D ctx->d_data; - ctx->cword.encrypt.keygen =3D 1; - ctx->cword.decrypt.keygen =3D 1; + if (aes_expandkey(&gen_aes, in_key, key_len)) + return -EINVAL; =20 - if (aes_expandkey(&gen_aes, in_key, key_len)) - return -EINVAL; - - memcpy(ctx->E, gen_aes.key_enc, AES_MAX_KEYLENGTH); - memcpy(ctx->D, gen_aes.key_dec, AES_MAX_KEYLENGTH); + memcpy(ctx->E, gen_aes.key_enc, AES_MAX_KEYLENGTH); + memcpy(ctx->D, gen_aes.key_dec, AES_MAX_KEYLENGTH); + } =20 -ok: for_each_online_cpu(cpu) if (&ctx->cword.encrypt =3D=3D per_cpu(paes_last_cword, cpu) || &ctx->cword.decrypt =3D=3D per_cpu(paes_last_cword, cpu)) --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 290164570E1 for ; Wed, 5 Aug 2026 11:58:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931111; cv=none; b=Jqav1HY+GaBiYFRtKPSfz7ygyfmm6yxk/4HBu4NYY6NWy5UQJpDxTnjbz/4orqLE2gmL6MlxjSfwcGEEEtJg37ZarNCAws7dsku4JVA4LwsPfiYjPX3LSno8XmKz81HHGVc3NmcN+nXUfN/mKTT7vnaDfnwm1kjMQF4HS36/TEk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931111; c=relaxed/simple; bh=H51eEndb83vlMBdSKdQPCJs4a0NhTn4ra/iT1GUYwIc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=u3ZBAIfj1yJ/a8Q8yTPgRRz6rlte8M5mE38/RxRqqj3hY1Z/X3+tTmyr4HeBPf7hDP4IRXjT/CnE3B+Vb5w0w7isQijECxS9UyyBNCPUqu7q/jEMXdHHmLVKXyXxazReSYpOjP1O7zZH3n8CIgZDvIGAP31LZLOH6PqXM1IXLgM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=BWS9EsHW; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="BWS9EsHW" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931109; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UgOea8COfMWPGkNwdk17UcXroZGUrewDpcR0b9Y5VNk=; b=BWS9EsHWXSbvKw9ZHYANWIFEi+ngc6/Q4FxVGR+gCyj5sRb0fbFLji8WJXWIVESkRstreS Vai/R3V7iMWxGl+GmS3n19hTwtusRCZbMI5nOq6O7YN5hsTXyERDexiv7p93RPHr6ocRuV AqhIu4Zs30BQ+hkY7LLogW0TGiR8d2k= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-270-2v7u31WwMPGBaCLd03fz4g-1; Wed, 05 Aug 2026 07:58:09 -0400 X-MC-Unique: 2v7u31WwMPGBaCLd03fz4g-1 X-Mimecast-MFC-AGG-ID: 2v7u31WwMPGBaCLd03fz4g_1785931088 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C1F951956096; Wed, 5 Aug 2026 11:58:08 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 06BBB30001A2; Wed, 5 Aug 2026 11:58:06 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org Cc: Eric Biggers Subject: [PATCH v3 05/10] crypto: sa2ul - clear the crypto_aes_ctx when done Date: Wed, 5 Aug 2026 13:57:43 +0200 Message-ID: <20260805115749.392672-6-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- drivers/crypto/sa2ul.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c index d865fd4a098cb..f1a7c2cc7a1af 100644 --- a/drivers/crypto/sa2ul.c +++ b/drivers/crypto/sa2ul.c @@ -465,7 +465,7 @@ static void sa_prepare_iopads(struct algo_data *data, c= onst u8 *key, /* Derive the inverse key used in AES-CBC decryption operation */ static inline int sa_aes_inv_key(u8 *inv_key, const u8 *key, u16 key_sz) { - struct crypto_aes_ctx ctx; + struct crypto_aes_ctx ctx __cleanup(aes_zeroize_ctx); int key_pos; =20 if (aes_expandkey(&ctx, key, key_sz)) { --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 656B344BCAF for ; Wed, 5 Aug 2026 11:58:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931099; cv=none; b=INCm/ylaqtDwcyZ+b45PWu3mefRhueVDY7iYgzqnzxDiCu3oJrGdVLUxjGl0d4rCQ+q87IskWqLe8NT96sTJpKur5yh/U+cKtfFTIv0NuYjX4pJxnE3ovWR0kR7/JMiXX42ppgQKO6JPZ6kL7LEbkQ5RDlWrNyOFC/iO4w1Vig8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931099; c=relaxed/simple; bh=b5aZNIDCHkvfoWtjbjEcQ7aD9yQG5oyRD+0JfQ4XMl8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CrdpUn1I1geZS7pGNGW5oBUj2S0lvxS3jbxEaAatTzTglCb48Dxm8pWoOMh93ZjB61Bhyt9SxWgRmtLqCMOLkxgkpDEV/2BnPtb8RegOK6nZYAUXNd2GVPYl+FjGRGa9U+iTwkni8ESzgmWtDOkChvaqNnMwebZ1JcWexyPXNHY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Zmq21Obl; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Zmq21Obl" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931097; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Vqj916x7IWEPwY8/O5oc6WAr80znZJ+nk/7CTdbfDAQ=; b=Zmq21Oblp9J0URoV1DM3b4qM1xGxJdVuGf2Np5+ql/7EwA/ogmC0CAV2QGEj9GNcOs4l3X hBnR6e2gHyXVVOdijxGhLBBFJR7SuDl1dwKzMb4di3QbBFaF/n8fTwN4Z8NECR3ulU28cG cmWvshagaOhbV65CgmIZq198aFr2mj8= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-677-CL75TcqEN6SAvxm2cteRWw-1; Wed, 05 Aug 2026 07:58:14 -0400 X-MC-Unique: CL75TcqEN6SAvxm2cteRWw-1 X-Mimecast-MFC-AGG-ID: CL75TcqEN6SAvxm2cteRWw_1785931093 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 463451956088; Wed, 5 Aug 2026 11:58:12 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5665830001A2; Wed, 5 Aug 2026 11:58:09 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Russell King , linux-arm-kernel@lists.infradead.org Cc: Eric Biggers Subject: [PATCH v3 06/10] crypto: arm/aes-neonbs - clear the crypto_aes_ctx when done Date: Wed, 5 Aug 2026 13:57:44 +0200 Message-ID: <20260805115749.392672-7-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- arch/arm/crypto/aes-neonbs-glue.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm/crypto/aes-neonbs-glue.c b/arch/arm/crypto/aes-neonbs= -glue.c index c49ddafc54f34..f0c8bfd2ac8fc 100644 --- a/arch/arm/crypto/aes-neonbs-glue.c +++ b/arch/arm/crypto/aes-neonbs-glue.c @@ -60,7 +60,7 @@ static int aesbs_setkey(struct crypto_skcipher *tfm, cons= t u8 *in_key, unsigned int key_len) { struct aesbs_ctx *ctx =3D crypto_skcipher_ctx(tfm); - struct crypto_aes_ctx rk; + struct crypto_aes_ctx rk __cleanup(aes_zeroize_ctx); int err; =20 err =3D aes_expandkey(&rk, in_key, key_len); --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 54EB443F0BC for ; Wed, 5 Aug 2026 11:58:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931102; cv=none; b=rhwcisQfXwE+RgRRH8/wL/1HSXyO46tZ9ZAcpDTmKj33bOSvCg9b4gbcjWexZeg5GFn9+adN5nJDEpZc8IEPKhUHwkhLmF8QWecLysBiM+KJTJW9WTiaY5jTyqaLeeoLwV1TB1GGHs+r00P+khneBdQ/XspwNwaGeYl2nhpkbtY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931102; c=relaxed/simple; bh=TXi1E78cjlAEwfYKo16gnIGsjCugY7q4hnj/efQOZ4k=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XBGNMfK3iMsr1mp9xYUOlincD7bh0vz93j7pWu0C/tiFte8xNqf9wkIXr6RQHQskJaTwtfe27lBG5cnglxoy9oCEvPGCRadmQ1Brjh8eWsL2nQ4VkmhBO5L7n/UMepkCQ4RvmqHELNwKfgCrCyJQOmfNfHl63hBj+gD6+gt6iMw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=MGzl4Rwk; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="MGzl4Rwk" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931100; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=D6NyyqK7KlyD8z4FwO/BXzdfa/BL5mjoIdYzF1ekpFM=; b=MGzl4RwkSUW8xYMphMqArZ2EosYI6R7uRE2jcFgbQKZpzLHRAg3XXE3bI5NyO+lI+beGeI dtIh+cJT2MJLyxwN431MW0IIzXS4ibJDk+kubU9I8xVV2KO4NcIhMgFibPai29zzkdq7m2 R6tpJLPlIFc8BA91rhnAwIG6f6yy6+M= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-17-GeXVgMZBM0-LiOv6q7OUsA-1; Wed, 05 Aug 2026 07:58:17 -0400 X-MC-Unique: GeXVgMZBM0-LiOv6q7OUsA-1 X-Mimecast-MFC-AGG-ID: GeXVgMZBM0-LiOv6q7OUsA_1785931095 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C09051955F21; Wed, 5 Aug 2026 11:58:15 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id CE72D30002E9; Wed, 5 Aug 2026 11:58:12 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org Cc: Eric Biggers Subject: [PATCH v3 07/10] crypto: arm64/aes-neonbs - clear the crypto_aes_ctx when done Date: Wed, 5 Aug 2026 13:57:45 +0200 Message-ID: <20260805115749.392672-8-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- arch/arm64/crypto/aes-neonbs-glue.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm64/crypto/aes-neonbs-glue.c b/arch/arm64/crypto/aes-ne= onbs-glue.c index 5bcbac9798931..c2f3eac0ca661 100644 --- a/arch/arm64/crypto/aes-neonbs-glue.c +++ b/arch/arm64/crypto/aes-neonbs-glue.c @@ -247,7 +247,7 @@ static int aesbs_xts_setkey(struct crypto_skcipher *tfm= , const u8 *in_key, unsigned int key_len) { struct aesbs_xts_ctx *ctx =3D crypto_skcipher_ctx(tfm); - struct crypto_aes_ctx rk; + struct crypto_aes_ctx rk __cleanup(aes_zeroize_ctx); int err; =20 err =3D xts_verify_key(tfm, in_key, key_len); --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93A7644C4F5 for ; Wed, 5 Aug 2026 11:58:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931106; cv=none; b=NRPWQM7JUuGPVm28+9+5T5LnZKUNh+jgN5Gxu9yghm//64hizyd/ObVrUmFlz9xWUsc5KjAJufIIolstLjnqvt5uDXy2uVFGJUKCBCVKo+6kCIF8xo/6b0oYT7bUU/3PshZwi6SC/5oE3nReNNc2eUvemktXfW7ZdGUP4NlB+qk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931106; c=relaxed/simple; bh=sgrWOcBFo9Sd2WuA0nVAH1BFjCA3yxoLh5SvhbCkwfg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=C2740IQW7Q2lRrzlQ3SoacIuPdtqT4TQZa7oiMdqZBBsQ3+2bhtE54eKFtMt7iQ3pVq6RZ4XnX07FzAHIuG/tgt7YmcfF7mfuFGf7Y2hhyqQKtAWueiDKb9w+Qidv7IQcaiGWg+eEEBTVeMEBxpsxWrpBHoUECtTW1KaKCxZTQg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=DwubdNQ1; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="DwubdNQ1" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931103; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JpzU2gD6nS7CuMmMhQxgVG5WsJfE9oTaObIb5LgkYdE=; b=DwubdNQ1Z6j5lIWqGyByxokonT0YD6lEZ4IKVxsBjsCaxcTCvFbo1Z3MBzSe8ih1Ei6TXD ekd30L/7kazRh4yITYZeI0Xu7PT2bxbUHmeNLaSHgKbW4mbhw7CpCn92hF8HOFwQ6FhP2E WUREQ8Ygk9hLzWZiC56MW/jZ/Ww4uSM= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-153-qMlZiLTnP1WpjyalZ7PoVQ-1; Wed, 05 Aug 2026 07:58:20 -0400 X-MC-Unique: qMlZiLTnP1WpjyalZ7PoVQ-1 X-Mimecast-MFC-AGG-ID: qMlZiLTnP1WpjyalZ7PoVQ_1785931098 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 80FB218007F0; Wed, 5 Aug 2026 11:58:18 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 52A0F30001A2; Wed, 5 Aug 2026 11:58:16 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Giovanni Cabiddu , qat-linux@intel.com Cc: Eric Biggers Subject: [PATCH v3 08/10] crypto: qat - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx) Date: Wed, 5 Aug 2026 13:57:46 +0200 Message-ID: <20260805115749.392672-9-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth A recent patch by Giovanni Cabiddu already added a memzero_explicit() for the crypto_aes_ctx in the qat_alg_xts_reverse_key() function, but since we introduced __cleanup(aes_zeroize_ctx) markers in previous commits in many spots of the code already, let's use it here now, too, to have the same code pattern everywhere. Cc: Giovanni Cabiddu Signed-off-by: Thomas Huth --- drivers/crypto/intel/qat/qat_common/qat_algs.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/crypto/intel/qat/qat_common/qat_algs.c b/drivers/crypt= o/intel/qat/qat_common/qat_algs.c index 91663805d9e60..cb669fb661625 100644 --- a/drivers/crypto/intel/qat/qat_common/qat_algs.c +++ b/drivers/crypto/intel/qat/qat_common/qat_algs.c @@ -388,7 +388,7 @@ static void qat_alg_skcipher_init_enc(struct qat_alg_sk= cipher_ctx *ctx, static void qat_alg_xts_reverse_key(const u8 *key_forward, unsigned int ke= ylen, u8 *key_reverse) { - struct crypto_aes_ctx aes_expanded; + struct crypto_aes_ctx aes_expanded __cleanup(aes_zeroize_ctx); int nrounds; u8 *key; =20 @@ -405,7 +405,6 @@ static void qat_alg_xts_reverse_key(const u8 *key_forwa= rd, unsigned int keylen, memcpy(key_reverse + AES_BLOCK_SIZE, key - AES_BLOCK_SIZE, AES_BLOCK_SIZE); } - memzero_explicit(&aes_expanded, sizeof(aes_expanded)); } =20 static void qat_alg_skcipher_init_dec(struct qat_alg_skcipher_ctx *ctx, --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CF42F44AB72 for ; Wed, 5 Aug 2026 11:58:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931109; cv=none; b=WruGN8yCNwB3yevJhrixwNyDuinWzCn3sxdVu7WDI9yZzHaixvoBTr7bGzLQ920lfVLbL+NpzUnY6Y2JK6Wj3LbHRED+MFPP6LgemR7vm5Mt8M+qZeY8snNa/oa2WPAn3sTIzRCDuIX4q5CQdyNUveSl/aG0J7PMCdzV9LaSYfA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931109; c=relaxed/simple; bh=IK4xsnh4ssKjWR3bDMNecBN2EiSBu8pzleD12h00ILo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MQK2VQlvDkLCyUKV7IqhLG7Kp6g+shmTHF7Xue38MlvhUS2XdgUpp3GI6cRI3fGMBqG0CsXVah/esKrKy2ZLgckMVDJsTxfJHKwf16ZbBn/jWAilxc9P0+Tr/ydi73pmAsGj3fml0QvNp2GrzvsU2oqE0X61dspdDigcXBbvbiw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Qqin1Tjd; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Qqin1Tjd" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931106; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=86lv8vKbl5o7itk5tJzGGW3/CxuVPVdslolT7Ezrhts=; b=Qqin1Tjda62QUNiRngFxGbWUyyW1dCbT1bBxwNEB2UY2oASC19qh6FOreKd4oTmdvKlaXL cqCLrTzkF7xaNF5qe1PANWpcQtP+gBVBmTScFtETQmUKYTEVkW9UZNmd2VvRRIal4QyYUn bh04pGyJJmp33WjPGPSYLh7XOwfNLuY= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-220-m7q0VKqxPR-1-OkUGiiGxg-1; Wed, 05 Aug 2026 07:58:22 -0400 X-MC-Unique: m7q0VKqxPR-1-OkUGiiGxg-1 X-Mimecast-MFC-AGG-ID: m7q0VKqxPR-1-OkUGiiGxg_1785931101 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0CCD01955DC5; Wed, 5 Aug 2026 11:58:21 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1B16730001A2; Wed, 5 Aug 2026 11:58:18 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Antoine Tenart Cc: Eric Biggers Subject: [PATCH v3 09/10] crypto: safexcel - Rework cleanup of sensitive structs in safexcel_aead_setkey Date: Wed, 5 Aug 2026 13:57:47 +0200 Message-ID: <20260805115749.392672-10-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth The crypto_authenc_keys structure only contains pointers to keys, but not the key data itself. So explicitly clearing the structure at the end of safexcel_aead_setkey() is not really necessary. On the other hand, the crypto_aes_ctx might contain sensitive information, so this structure should be cleaned up at the end instead. Do this now via the new __cleanup(aes_zeroize_ctx) marker. Since __cleanup() and gotos should not be mixed in the same function, replace the gotos with early return statements, which is fine now that we dropped the memzero_explicit(&keys, sizeof(keys)) at the end. Suggested-by: Eric Biggers Signed-off-by: Thomas Huth --- .../crypto/inside-secure/safexcel_cipher.c | 27 ++++++++----------- 1 file changed, 11 insertions(+), 16 deletions(-) diff --git a/drivers/crypto/inside-secure/safexcel_cipher.c b/drivers/crypt= o/inside-secure/safexcel_cipher.c index a8349b684693e..e94686490bb27 100644 --- a/drivers/crypto/inside-secure/safexcel_cipher.c +++ b/drivers/crypto/inside-secure/safexcel_cipher.c @@ -407,17 +407,17 @@ static int safexcel_aead_setkey(struct crypto_aead *c= tfm, const u8 *key, struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; struct crypto_authenc_keys keys; - struct crypto_aes_ctx aes; - int err =3D -EINVAL, i; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); + int err, i; const char *alg; =20 if (unlikely(crypto_authenc_extractkeys(&keys, key, len))) - goto badkey; + return -EINVAL; =20 if (ctx->mode =3D=3D CONTEXT_CONTROL_CRYPTO_MODE_CTR_LOAD) { /* Must have at least space for the nonce here */ if (unlikely(keys.enckeylen < CTR_RFC3686_NONCE_SIZE)) - goto badkey; + return -EINVAL; /* last 4 bytes of key are the nonce! */ ctx->nonce =3D *(u32 *)(keys.enckey + keys.enckeylen - CTR_RFC3686_NONCE_SIZE); @@ -430,25 +430,25 @@ static int safexcel_aead_setkey(struct crypto_aead *c= tfm, const u8 *key, case SAFEXCEL_DES: err =3D verify_aead_des_key(ctfm, keys.enckey, keys.enckeylen); if (unlikely(err)) - goto badkey; + return err; break; case SAFEXCEL_3DES: err =3D verify_aead_des3_key(ctfm, keys.enckey, keys.enckeylen); if (unlikely(err)) - goto badkey; + return err; break; case SAFEXCEL_AES: err =3D aes_expandkey(&aes, keys.enckey, keys.enckeylen); if (unlikely(err)) - goto badkey; + return err; break; case SAFEXCEL_SM4: if (unlikely(keys.enckeylen !=3D SM4_KEY_SIZE)) - goto badkey; + return err; break; default: dev_err(priv->dev, "aead: unsupported cipher algorithm\n"); - goto badkey; + return -EINVAL; } =20 if (priv->flags & EIP197_TRC_CACHE && ctx->base.ctxr_dma) { @@ -486,24 +486,19 @@ static int safexcel_aead_setkey(struct crypto_aead *c= tfm, const u8 *key, break; default: dev_err(priv->dev, "aead: unsupported hash algorithm\n"); - goto badkey; + return -EINVAL; } =20 if (safexcel_hmac_setkey(&ctx->base, keys.authkey, keys.authkeylen, alg, ctx->state_sz)) - goto badkey; + return -EINVAL; =20 /* Now copy the keys into the context */ for (i =3D 0; i < keys.enckeylen / sizeof(u32); i++) ctx->key[i] =3D cpu_to_le32(((u32 *)keys.enckey)[i]); ctx->key_len =3D keys.enckeylen; =20 - memzero_explicit(&keys, sizeof(keys)); return 0; - -badkey: - memzero_explicit(&keys, sizeof(keys)); - return err; } =20 static int safexcel_context_control(struct safexcel_cipher_ctx *ctx, --=20 2.55.0 From nobody Fri Oct 2 04:27:21 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D1C5A4519B2 for ; Wed, 5 Aug 2026 11:58:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931108; cv=none; b=TsOx8KlitK7qptnuTXatLE4CMGSqVBWRU167x7rwC65BA2jNytycIom0Qnlc47gqVfsBmCAl3AYNG3iXfY88R5jbQoFSTQhTwhjVPILUgoBeZrnTTFesOFp6btltrImEYOV+5WZPojuqH9bE/5yIqcCxBcDTXcl4XFNMdtbu6cM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785931108; c=relaxed/simple; bh=L8ZpOpEgHP/uX6NDcQAlL46I/EkO9GCCwX+fBds8aQ4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SKLZMYJ7Mi9wdDHTPZALN497yrZl0k6/YwEH02BXwd5ueVFT4tEA/SfKofmOXlrIBMgqTtz5m5cmhO5JeTAHFgfHys7e7478CN+ZizL8OYC8jzqgrwH9y8unzjs5Oe33g7bjSxzQgkho7bMtEnASTiBPUeP6iLRdmDZT2apULUw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=MwSi7uzk; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="MwSi7uzk" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785931106; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=jIa1q/rwVv4YV5P2Dz7HZPw1sN5kuVFBHsiGPLc7Ll0=; b=MwSi7uzkePwbtF8EDKBrD0HF/UFRB22XrrEb4aE2Y4UyIgcsatJUGblusKxL8828Aep1NE JGLevVeeVq10DgvFsB0Ndc5PxU+evFqvCMYi0kCST4/SfNR70Yv7piswNzO0aeyznpQUQ4 mtSNi8N1VHEMu4e1I+/x1Z4hj2hRs3g= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-384-O2e2e1G1MlqpJBIwaZCyfQ-1; Wed, 05 Aug 2026 07:58:24 -0400 X-MC-Unique: O2e2e1G1MlqpJBIwaZCyfQ-1 X-Mimecast-MFC-AGG-ID: O2e2e1G1MlqpJBIwaZCyfQ_1785931103 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9AD3D1956088; Wed, 5 Aug 2026 11:58:23 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.202]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A7E2930001A2; Wed, 5 Aug 2026 11:58:21 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org, Antoine Tenart Cc: Eric Biggers Subject: [PATCH v3 10/10] crypto: safexcel - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx) Date: Wed, 5 Aug 2026 13:57:48 +0200 Message-ID: <20260805115749.392672-11-thuth@redhat.com> In-Reply-To: <20260805115749.392672-1-thuth@redhat.com> References: <20260805115749.392672-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth The code clears the crypto_aes_ctx in most cases already with memzero_explicit(), but safexcel_skcipher_aesxts_setkey() runs aes_expandkey() twice, and in case the second call fails, the context from the first call is leaked. To fix this issue and to avoid future similar problems, let's use the new __cleanup(aes_zeroize_ctx) mechanism to make sure that we always clear the crypto_aes_ctx in all cases. Signed-off-by: Thomas Huth Acked-by: Antoine Tenart --- drivers/crypto/inside-secure/safexcel_cipher.c | 13 ++++--------- drivers/crypto/inside-secure/safexcel_hash.c | 3 +-- 2 files changed, 5 insertions(+), 11 deletions(-) diff --git a/drivers/crypto/inside-secure/safexcel_cipher.c b/drivers/crypt= o/inside-secure/safexcel_cipher.c index e94686490bb27..50e8792b399de 100644 --- a/drivers/crypto/inside-secure/safexcel_cipher.c +++ b/drivers/crypto/inside-secure/safexcel_cipher.c @@ -375,7 +375,7 @@ static int safexcel_skcipher_aes_setkey(struct crypto_s= kcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); @@ -396,7 +396,6 @@ static int safexcel_skcipher_aes_setkey(struct crypto_s= kcipher *ctfm, =20 ctx->key_len =3D len; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -1357,7 +1356,7 @@ static int safexcel_skcipher_aesctr_setkey(struct cry= pto_skcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; unsigned int keylen; =20 @@ -1383,7 +1382,6 @@ static int safexcel_skcipher_aesctr_setkey(struct cry= pto_skcipher *ctfm, =20 ctx->key_len =3D keylen; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -2537,7 +2535,7 @@ static int safexcel_skcipher_aesxts_setkey(struct cry= pto_skcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; unsigned int keylen; =20 @@ -2585,7 +2583,6 @@ static int safexcel_skcipher_aesxts_setkey(struct cry= pto_skcipher *ctfm, =20 ctx->key_len =3D keylen << 1; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -2751,12 +2748,11 @@ static int safexcel_aead_ccm_setkey(struct crypto_a= ead *ctfm, const u8 *key, struct crypto_tfm *tfm =3D crypto_aead_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); if (ret) { - memzero_explicit(&aes, sizeof(aes)); return ret; } =20 @@ -2785,7 +2781,6 @@ static int safexcel_aead_ccm_setkey(struct crypto_aea= d *ctfm, const u8 *key, else ctx->hash_alg =3D CONTEXT_CONTROL_CRYPTO_ALG_XCBC128; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 diff --git a/drivers/crypto/inside-secure/safexcel_hash.c b/drivers/crypto/= inside-secure/safexcel_hash.c index 3402e570d045c..20c17eb09495e 100644 --- a/drivers/crypto/inside-secure/safexcel_hash.c +++ b/drivers/crypto/inside-secure/safexcel_hash.c @@ -1905,7 +1905,7 @@ static int safexcel_cbcmac_setkey(struct crypto_ahash= *tfm, const u8 *key, unsigned int len) { struct safexcel_ahash_ctx *ctx =3D crypto_tfm_ctx(crypto_ahash_tfm(tfm)); - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); @@ -1928,7 +1928,6 @@ static int safexcel_cbcmac_setkey(struct crypto_ahash= *tfm, const u8 *key, } ctx->cbcmac =3D true; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 --=20 2.55.0