From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2286030DD22 for ; Fri, 7 Aug 2026 07:07:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086426; cv=none; b=nL/teUny6AtU/dHY6aDrtyPPtkoAHZT7DKJYHWDICgJ4hQD/7HL5nnJYgeSfLRFfoKp1WD4C+F2y6u9GPK5VxqlxlLJyMpu5AuTkZ9qwEq1bZKkQ6KTklTMLKo7oRZn0+haZgthCxvvYhkYnAtOy3A5mgMMezNpelCM8FjNwrLI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086426; c=relaxed/simple; bh=JaYULTHp2SPezfRmr9jErjWyHRHYwFH/4MCkUw7PxrI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FrcKcDJSjw83gmGAE/JfxrelE5WErv22B5E9bLsGvpiddObertN/f05cnXEfpWomtaFbaHi9u1LyNxfJ7mr/jpid4cnD/6fvzTLlgAXqQq87Ft9e+pIYgr3iGvxjxtQ0y57n1w8q+xWeY2bLp+/wmgLxzbKSm/tFEHDo2Yyx51w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=JWPvoSPj; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="JWPvoSPj" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086424; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fCdPX+LzHi81vXbH7hGFraeUcnuAFIfrwEq1PaejTQA=; b=JWPvoSPjsrPcvo6qNpeerdpS8luMfYRw77/G3gYapl4keeNYGuas1dMLGEy0MJr+TrDqxW BDASw1EG3JkDGViY+i0ecVxUmmjECN1bbK1+eLwBml9Ysf7tu35bLZ0ZNv8nDqSnPJXVw3 YNIrnQNesp/Jlr3JgQNismkN7wZVHF0= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-691-D_aGlKvqPWaXU44QL1n1iw-1; Fri, 07 Aug 2026 03:07:00 -0400 X-MC-Unique: D_aGlKvqPWaXU44QL1n1iw-1 X-Mimecast-MFC-AGG-ID: D_aGlKvqPWaXU44QL1n1iw_1786086419 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 151A21956078; Fri, 7 Aug 2026 07:06:59 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E3A17195DF92; Fri, 7 Aug 2026 07:06:56 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org Subject: [PATCH v4 01/10] crypto: Provide a wrapper function for zeroizing crypto_aes_ctx Date: Fri, 7 Aug 2026 09:06:28 +0200 Message-ID: <20260807070651.228713-2-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Several crypto drivers need to zeroize their local crypto_aes_ctx structures after use to avoid leaking key material on the stack. Currently some call sites do this with their own memzero_explicit() call, which is error-prone since it is easy to miss a return path (what already happened in some drivers). Some other call sites miss to clear crypto_aes_ctx completely. Provide an aes_zeroize_ctx() helper that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Acked-by: Eric Biggers Signed-off-by: Thomas Huth --- include/crypto/aes.h | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/include/crypto/aes.h b/include/crypto/aes.h index 3279cfa546085..eb970b8d623f9 100644 --- a/include/crypto/aes.h +++ b/include/crypto/aes.h @@ -159,6 +159,19 @@ static inline int aes_check_keylen(size_t keylen) int aes_expandkey(struct crypto_aes_ctx *ctx, const u8 *in_key, unsigned int key_len); =20 +/** + * aes_zeroize_ctx - Clear a crypto_aes_ctx structure + * @ctx: The location of the context that should be zeroized + * + * Explicitly fills the crypto_aes_ctx with zeroes. This should be done + * once the context is not required anymore to avoid that its contents + * are leaked on the stack or heap (if not using kfree_sensitive()). + */ +static inline void aes_zeroize_ctx(struct crypto_aes_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /* * The following functions are temporarily exported for use by the AES mode * implementations in arch/$(SRCARCH)/crypto/. These exports will go away= when --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 62D08324B32 for ; Fri, 7 Aug 2026 07:07:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086461; cv=none; b=PHGj9jL08Fe54Tb+Ky/v5zj0clhMov2JHIjYegkebVtl9+Ze+eFad67q1D8iyoFTSOKc70eLdZovnpdyt+kil/SgsFJLAjfhLMYn9+zON/X48wblQMZ5m0R4Qx5K/UHxliC2AYLA65qWfBzE3HxSK/GJptxT9Q3+m/WFH6tlFc4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086461; c=relaxed/simple; bh=WVt0qQ4+1eH0aK8H3LOcQUCnNbq+Qzdzr1yi2CdD+9o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qJf4NYjDt0bZ4RVrknKvlGSrEEI9KlVSjoO5Mr0fIi+633wgfxbnEemMmUQ+qpsgk4HRWzOJfyL2mwzq87R9gEQhp+rk9H+OPdRpdDl2PYbYkgYBssANCN7oa8eXf2EN3PZ2n6WHeij88/XIdOd1mH8RdRaF3MThjpnzEZgFBuU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=bLuzsKju; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="bLuzsKju" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086459; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=rFuj09l13bDJWP8ROOQNO6DWGBJe5ddETVvR3frCMgU=; b=bLuzsKju0tsP7vC6cfyF0g+HyrPWjeTAiEzMHi1IW/dQQavsbhTiCAd9CCKhJskBvu9Ait sPXhEJ/1MAfuc/4Y+3DeOY/0PkYEUIAKlW6niMz1uawt4hLG8r5ia5QIvAARgMmrzFvK68 iNYEvAsy65HN6Dg2ip8yfHryBCqd2a0= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-306-nXN2oDJ3M8CXiPfpwlk0eA-1; Fri, 07 Aug 2026 03:07:08 -0400 X-MC-Unique: nXN2oDJ3M8CXiPfpwlk0eA-1 X-Mimecast-MFC-AGG-ID: nXN2oDJ3M8CXiPfpwlk0eA_1786086427 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 09EF31800471; Fri, 7 Aug 2026 07:07:06 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A279C1956094; Fri, 7 Aug 2026 07:07:00 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Neal Liu , Joel Stanley , Andrew Jeffery Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org, linux-aspeed@lists.ozlabs.org, linux-arm-kernel@lists.infradead.org Subject: [PATCH v4 02/10] crypto: aspeed - clear the crypto_aes_ctx when done Date: Fri, 7 Aug 2026 09:06:29 +0200 Message-ID: <20260807070651.228713-3-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Declare the gen_aes_key with __cleanup(aes_zeroize_ctx) to avoid that its contents could be leaking via the stack when the function returns. And since it is only required in one branch of the if-statement there, move it to that block, too. Signed-off-by: Thomas Huth --- drivers/crypto/aspeed/aspeed-hace-crypto.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/crypto/aspeed/aspeed-hace-crypto.c b/drivers/crypto/as= peed/aspeed-hace-crypto.c index fa201dae1f81b..e7d3f611df05c 100644 --- a/drivers/crypto/aspeed/aspeed-hace-crypto.c +++ b/drivers/crypto/aspeed/aspeed-hace-crypto.c @@ -576,7 +576,6 @@ static int aspeed_aes_setkey(struct crypto_skcipher *ci= pher, const u8 *key, { struct aspeed_cipher_ctx *ctx =3D crypto_skcipher_ctx(cipher); struct aspeed_hace_dev *hace_dev =3D ctx->hace_dev; - struct crypto_aes_ctx gen_aes_key; =20 CIPHER_DBG(hace_dev, "keylen: %d bits\n", (keylen * 8)); =20 @@ -585,9 +584,9 @@ static int aspeed_aes_setkey(struct crypto_skcipher *ci= pher, const u8 *key, return -EINVAL; =20 if (ctx->hace_dev->version =3D=3D AST2500_VERSION) { + struct crypto_aes_ctx gen_aes_key __cleanup(aes_zeroize_ctx); aes_expandkey(&gen_aes_key, key, keylen); memcpy(ctx->key, gen_aes_key.key_enc, AES_MAX_KEYLENGTH); - } else { memcpy(ctx->key, key, keylen); } --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9D67A12B94 for ; Fri, 7 Aug 2026 07:07:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086438; cv=none; b=impnPI1uE5cCzp/jcWIcClvs4V26Ro+g3t8Q4O+y/SqCJMl7HehheMi2ULzi4ecnnyehRyq1cjAiLUn1Z5GCQzTP/1o7KjGlqYpvvXXFoo7mtoXf5Bo2HNY0PG51puFgl1AHh1a+5J1deDiLZpsUAB7/1AOj6u+Y2OVmoPGle6k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086438; c=relaxed/simple; bh=vzZOFKBz/vS1L4OiBZo1G1l389pu1nVzeo0UGyLy+sw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=uZrtQOsML/qCJg8SZrn43+7BwN2c39t/0cOGBqVwUb95ipMd6AL/XfsNyv5F75hipq7+QvsOoAlZ1XqVkwzs/raqin7CiC2eCXS05Z/AlaFnA/Raa4VpVxgoLmuf/vH7vXMNHCmvT9Kvg/sDf/BjiI8q8HA01I8+lI3tq2EW9o0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FPI0N2w3; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FPI0N2w3" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086436; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=5/FP2iona05c4GGFGjhMtKYGShx3GCcZ6CaDckfTOnk=; b=FPI0N2w3ePxF46/Dobrj5Kd7/kj9Ljjc13rOgTkCKg6acNu5xarhNIEhfT98VpVwZPJx5c n2pvQ4KXEEAcailAk5fsl4mZP9SWupIt7RO/89KKa54rDDVZAlt1RuOmMuTiQ7LvPiVAxD A1X8lBYX0w+DMXQqWvpGez1Sn01gmbE= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-472-q9USIYrkOlK2hezRTxpaIA-1; Fri, 07 Aug 2026 03:07:13 -0400 X-MC-Unique: q9USIYrkOlK2hezRTxpaIA-1 X-Mimecast-MFC-AGG-ID: q9USIYrkOlK2hezRTxpaIA_1786086432 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id F0E7A195608F; Fri, 7 Aug 2026 07:07:11 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EC9A51956094; Fri, 7 Aug 2026 07:07:07 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Christian Marangi , Antoine Tenart Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org Subject: [PATCH v4 03/10] crypto: inside-secure/eip93 - clear the crypto_aes_ctx when done Date: Fri, 7 Aug 2026 09:06:30 +0200 Message-ID: <20260807070651.228713-4-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- drivers/crypto/inside-secure/eip93/eip93-aead.c | 2 +- drivers/crypto/inside-secure/eip93/eip93-cipher.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/crypto/inside-secure/eip93/eip93-aead.c b/drivers/cryp= to/inside-secure/eip93/eip93-aead.c index 2bbd0af7b0e0e..973cebef5df37 100644 --- a/drivers/crypto/inside-secure/eip93/eip93-aead.c +++ b/drivers/crypto/inside-secure/eip93/eip93-aead.c @@ -92,7 +92,7 @@ static int eip93_aead_setkey(struct crypto_aead *ctfm, co= nst u8 *key, struct crypto_tfm *tfm =3D crypto_aead_tfm(ctfm); struct eip93_crypto_ctx *ctx =3D crypto_tfm_ctx(tfm); struct crypto_authenc_keys keys; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); struct sa_record *sa_record =3D ctx->sa_record; u32 nonce =3D 0; int ret; diff --git a/drivers/crypto/inside-secure/eip93/eip93-cipher.c b/drivers/cr= ypto/inside-secure/eip93/eip93-cipher.c index 4dd7ab7503e85..7051b99ee6235 100644 --- a/drivers/crypto/inside-secure/eip93/eip93-cipher.c +++ b/drivers/crypto/inside-secure/eip93/eip93-cipher.c @@ -116,7 +116,7 @@ static int eip93_skcipher_setkey(struct crypto_skcipher= *ctfm, const u8 *key, } =20 if (flags & EIP93_ALG_AES) { - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); =20 ctx->blksize =3D AES_BLOCK_SIZE; ret =3D aes_expandkey(&aes, key, keylen); --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D7FBA311C2D for ; Fri, 7 Aug 2026 07:07:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086450; cv=none; b=A/7a0zKGacmQOvMVL1/AvGITyfGpwMIKsc37S1ygWQ8zj0n0kgQDGXU8untJ2IIRr92vdZLNRFNXkyD/aoi+GEFX77Ulp8LFVw5x9XKoRQ+cOPiOdqibG3ayxyWdyE2DOekSiv0kEtFwlnIiYvg3/WxpZh9a6L2Bu/JlBi/CYkQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086450; c=relaxed/simple; bh=rrHOeIvGuTbxvBxf0sD+S1Wa6q8TEDfmgAXE4+BZst4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pH5p4EY4QJ5SE1fEKne2FAOF+CgBiDiDfCTyUs011PttmUWV7Q8uIdcvH22hi+3P9BF9/xzQIet9Q2dOPl9AJRMMJaSoOTk4Px9efgwEiyvXTEorkUzDKTQ338clGOZgOk0xjZzjpdUbbOxajtK4Ymnb08i+Ldb38guf8TcyFTI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=iPYjbwDP; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="iPYjbwDP" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086446; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=dFIxmKcUsq1WalhKwXv0wsQgLSJrF7IelNY2pEdEa3U=; b=iPYjbwDPuzO6FtiZf5MGTladptfd9oACe1XIQNzQWzXOg3RjX417dg+2ysN/cgfGtphU5M 6DWhlBN4Ft8ll8uzsY+nLC2CwtHzz6pO1JDUxxci4IMYNVMo3n+eIo9m4ZgKPGEtObw7uP IDxUGDJzWSA/2im4jyC2ahiVbMs0Icc= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-687-vF4XTtHUOtq9Lc1s9CYOUA-1; Fri, 07 Aug 2026 03:07:17 -0400 X-MC-Unique: vF4XTtHUOtq9Lc1s9CYOUA-1 X-Mimecast-MFC-AGG-ID: vF4XTtHUOtq9Lc1s9CYOUA_1786086436 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id F151B1800867; Fri, 7 Aug 2026 07:07:15 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 09B221956094; Fri, 7 Aug 2026 07:07:13 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org Subject: [PATCH v4 04/10] crypto: padlock-aes - clear the crypto_aes_ctx when done Date: Fri, 7 Aug 2026 09:06:31 +0200 Message-ID: <20260807070651.228713-5-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. And since __cleanup() (and __free()) should not be mixed with "gotos" in the same function, turn the goto statement here into a proper block of the related if-statement. Signed-off-by: Thomas Huth --- drivers/crypto/padlock-aes.c | 22 ++++++++++------------ 1 file changed, 10 insertions(+), 12 deletions(-) diff --git a/drivers/crypto/padlock-aes.c b/drivers/crypto/padlock-aes.c index 1be549a07a219..400a889e924d7 100644 --- a/drivers/crypto/padlock-aes.c +++ b/drivers/crypto/padlock-aes.c @@ -109,7 +109,7 @@ static int aes_set_key(struct crypto_tfm *tfm, const u8= *in_key, { struct aes_ctx *ctx =3D aes_ctx(tfm); const __le32 *key =3D (const __le32 *)in_key; - struct crypto_aes_ctx gen_aes; + struct crypto_aes_ctx gen_aes __cleanup(aes_zeroize_ctx); int cpu; =20 if (key_len % 8) @@ -137,20 +137,18 @@ static int aes_set_key(struct crypto_tfm *tfm, const = u8 *in_key, ctx->cword.decrypt.ksize =3D ctx->cword.encrypt.ksize; =20 /* Don't generate extended keys if the hardware can do it. */ - if (aes_hw_extkey_available(key_len)) - goto ok; + if (!aes_hw_extkey_available(key_len)) { + ctx->D =3D ctx->d_data; + ctx->cword.encrypt.keygen =3D 1; + ctx->cword.decrypt.keygen =3D 1; =20 - ctx->D =3D ctx->d_data; - ctx->cword.encrypt.keygen =3D 1; - ctx->cword.decrypt.keygen =3D 1; + if (aes_expandkey(&gen_aes, in_key, key_len)) + return -EINVAL; =20 - if (aes_expandkey(&gen_aes, in_key, key_len)) - return -EINVAL; - - memcpy(ctx->E, gen_aes.key_enc, AES_MAX_KEYLENGTH); - memcpy(ctx->D, gen_aes.key_dec, AES_MAX_KEYLENGTH); + memcpy(ctx->E, gen_aes.key_enc, AES_MAX_KEYLENGTH); + memcpy(ctx->D, gen_aes.key_dec, AES_MAX_KEYLENGTH); + } =20 -ok: for_each_online_cpu(cpu) if (&ctx->cword.encrypt =3D=3D per_cpu(paes_last_cword, cpu) || &ctx->cword.decrypt =3D=3D per_cpu(paes_last_cword, cpu)) --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3D4C7145A1F for ; Fri, 7 Aug 2026 07:07:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086454; cv=none; b=QYPKRjce1a2WxF69JVILiHY6h39HURl1FZ8CsJFzA2kTeRkh3GOAAL7LNEtp+Tfw1GKTRHdKwNgOo4+V8eDt8rQ8eFbKx4GyxrHRpSJyTnNfPMf1E17lyxxEsfYi/xu/+YYHMsPcrQ9hBo1mdR3+AIp/v+TEmpmS8k6XgnFyG7Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086454; c=relaxed/simple; bh=H51eEndb83vlMBdSKdQPCJs4a0NhTn4ra/iT1GUYwIc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=K0s3u0p6atkHs1fBiLQQvIUJe4RppCCBWThnTiDsAaa0Gk9SjLBPanrYWOKnaig/kUTN5u47hwu4V7drwkgZX/Wwl8X5YcHg3POws34fnnhrFjYhzagPg3YoG5M712OPS8xcRy0pWYLjeBA4BASDKpnN8zGCwNpPTXwQEcoEOmY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=TTMC30CR; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="TTMC30CR" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086452; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UgOea8COfMWPGkNwdk17UcXroZGUrewDpcR0b9Y5VNk=; b=TTMC30CRfiDXkA5/KT6X+5LOJb4f1+snA4qlKw0gIm4s5WooHpuBsY+L539W78O86UwHfq l4J38PMGAssgF4sfjRpym6RdP3QMDJDrRY6BK9Vnt6el90ODfED8AZfztx+2rw6Lm/Oozh CggE3S447nhTW6Gn5ha9SJZUgimJ+kc= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-321-UEauz07_N9eY3qABqt7ZmQ-1; Fri, 07 Aug 2026 03:07:20 -0400 X-MC-Unique: UEauz07_N9eY3qABqt7ZmQ-1 X-Mimecast-MFC-AGG-ID: UEauz07_N9eY3qABqt7ZmQ_1786086439 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 995C51800646; Fri, 7 Aug 2026 07:07:19 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 7D7ED1956094; Fri, 7 Aug 2026 07:07:17 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org Subject: [PATCH v4 05/10] crypto: sa2ul - clear the crypto_aes_ctx when done Date: Fri, 7 Aug 2026 09:06:32 +0200 Message-ID: <20260807070651.228713-6-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- drivers/crypto/sa2ul.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c index d865fd4a098cb..f1a7c2cc7a1af 100644 --- a/drivers/crypto/sa2ul.c +++ b/drivers/crypto/sa2ul.c @@ -465,7 +465,7 @@ static void sa_prepare_iopads(struct algo_data *data, c= onst u8 *key, /* Derive the inverse key used in AES-CBC decryption operation */ static inline int sa_aes_inv_key(u8 *inv_key, const u8 *key, u16 key_sz) { - struct crypto_aes_ctx ctx; + struct crypto_aes_ctx ctx __cleanup(aes_zeroize_ctx); int key_pos; =20 if (aes_expandkey(&ctx, key, key_sz)) { --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4CA04380FC7 for ; Fri, 7 Aug 2026 07:07:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086455; cv=none; b=aO7W8ZOA9tbs7GtIhp9V81NV9raO4XYIIOUS2uTvm9tu+Jjua7vzElmlU6F43FtS7spBZHv6xHFuN3NHJaV8xl8n4exmR2925z6Za/EFVa8260XQV094ZMRRcYem3fzjw4UBteTrf4/WUgw7sx+R7vw9up0sFjulnQ5qfUf0Srw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086455; c=relaxed/simple; bh=b5aZNIDCHkvfoWtjbjEcQ7aD9yQG5oyRD+0JfQ4XMl8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lBjxUCqkOZ1hxKSyXbNvHpP/+D8evGPIGSI8p2xXfZ9PtyQT4zjLe9kuFSzWkcwUQMG8KqjblwHu8c8L3ZtCg4z5aE9TasVSHFyYKN6oqQp5o/taagzfwqI2+J/dwooPifV7QMt6p8xGSz0pgBnLKZigm2Xihkyx8bNWp8zkhmw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FeK4vhcA; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FeK4vhcA" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086453; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Vqj916x7IWEPwY8/O5oc6WAr80znZJ+nk/7CTdbfDAQ=; b=FeK4vhcAgs4FhQnP5LW2WmwCIOcqBVa14LeluOmsfSxitNcSQXMNpe7Y1UFvvHxGikTG/2 mAOyAuWlkPeXPY9EtbZGoyjOjAe21L+gnKJr0cWFNyG26gcFdTjUCPgHlnoGqLO2pEwVrA UO2OoahT/TX5E/XV9sVa7bBQBMItYfU= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-76-yuNjvHM6PTa9_E8jKbh68g-1; Fri, 07 Aug 2026 03:07:27 -0400 X-MC-Unique: yuNjvHM6PTa9_E8jKbh68g-1 X-Mimecast-MFC-AGG-ID: yuNjvHM6PTa9_E8jKbh68g_1786086446 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C186A1800471; Fri, 7 Aug 2026 07:07:24 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0DF841956094; Fri, 7 Aug 2026 07:07:20 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Russell King Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org Subject: [PATCH v4 06/10] crypto: arm/aes-neonbs - clear the crypto_aes_ctx when done Date: Fri, 7 Aug 2026 09:06:33 +0200 Message-ID: <20260807070651.228713-7-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- arch/arm/crypto/aes-neonbs-glue.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm/crypto/aes-neonbs-glue.c b/arch/arm/crypto/aes-neonbs= -glue.c index c49ddafc54f34..f0c8bfd2ac8fc 100644 --- a/arch/arm/crypto/aes-neonbs-glue.c +++ b/arch/arm/crypto/aes-neonbs-glue.c @@ -60,7 +60,7 @@ static int aesbs_setkey(struct crypto_skcipher *tfm, cons= t u8 *in_key, unsigned int key_len) { struct aesbs_ctx *ctx =3D crypto_skcipher_ctx(tfm); - struct crypto_aes_ctx rk; + struct crypto_aes_ctx rk __cleanup(aes_zeroize_ctx); int err; =20 err =3D aes_expandkey(&rk, in_key, key_len); --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 315A8390CBE for ; Fri, 7 Aug 2026 07:07:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086456; cv=none; b=aXg/NdLNHKypO5X/aDn1k4i5QkDLpSGjNnKNnC6eHfPDBY6LsTu2PV/yngPQzu/+MLv28ebC23JKuag4oFM2q4ITb0MKdCkRTy86UZ7da4LP1J+jyz+UaFkO2E0cefY3IxlfWw3NIDmOG/Uen98R4/DgIxKfi/phbvSTD55Bbp0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086456; c=relaxed/simple; bh=TXi1E78cjlAEwfYKo16gnIGsjCugY7q4hnj/efQOZ4k=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rrmLfjwJhQzXbjnGVsv4mBH2CgLF5uFBii+Fa2RwOu5OVn1LDJ7BGGi97P63Za4pCAgup9K2q0px3G637jjDLlQFE4PnqGd4Ty1mo8rcSu5oWvsfzOw17L+wGtYZjGpN11d5/GDkbiVtKoMiNStwKMxM9NQFugz2fe0EUheghEA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=gnvLrvwu; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="gnvLrvwu" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086454; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=D6NyyqK7KlyD8z4FwO/BXzdfa/BL5mjoIdYzF1ekpFM=; b=gnvLrvwusTHRblydfji46j9Jj7kUtVuCB1I3S7nlqbfw/+ecGLGZ3m83gRZhJY/ljVqRZ9 n4OY/sOIonXun/ADLlmicQ/Iv9cdrGTbvAzok33+mBi2YRaV0CumtnVu+iB84rG4HsC9V5 QLz+MIxLkw8ond0rTKBbv2i34fcfq3Y= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-280-XVYdn7r6OtmkJxuEHP0pwg-1; Fri, 07 Aug 2026 03:07:30 -0400 X-MC-Unique: XVYdn7r6OtmkJxuEHP0pwg-1 X-Mimecast-MFC-AGG-ID: XVYdn7r6OtmkJxuEHP0pwg_1786086449 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5EF26195605E; Fri, 7 Aug 2026 07:07:29 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 545201956094; Fri, 7 Aug 2026 07:07:25 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Catalin Marinas , Will Deacon Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org Subject: [PATCH v4 07/10] crypto: arm64/aes-neonbs - clear the crypto_aes_ctx when done Date: Fri, 7 Aug 2026 09:06:34 +0200 Message-ID: <20260807070651.228713-8-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the crypto_aes_ctx structure via __cleanup(aes_zeroize_ctx) when we're done with it to avoid that key data could leak on the stack. Signed-off-by: Thomas Huth --- arch/arm64/crypto/aes-neonbs-glue.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm64/crypto/aes-neonbs-glue.c b/arch/arm64/crypto/aes-ne= onbs-glue.c index 5bcbac9798931..c2f3eac0ca661 100644 --- a/arch/arm64/crypto/aes-neonbs-glue.c +++ b/arch/arm64/crypto/aes-neonbs-glue.c @@ -247,7 +247,7 @@ static int aesbs_xts_setkey(struct crypto_skcipher *tfm= , const u8 *in_key, unsigned int key_len) { struct aesbs_xts_ctx *ctx =3D crypto_skcipher_ctx(tfm); - struct crypto_aes_ctx rk; + struct crypto_aes_ctx rk __cleanup(aes_zeroize_ctx); int err; =20 err =3D xts_verify_key(tfm, in_key, key_len); --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 30B64389114 for ; Fri, 7 Aug 2026 07:07:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086461; cv=none; b=d8o8I2t9jsoDclXo4KM6dGRgKYwV63IDW5c+Yc72kljAdn52ltABJUDbPST/xET+I1cLMXriEsguO3xVrl//UQs8ngoLEB63BhKUKoT6e4EJ1kokqj00D8IvD+nhzP49g+7lYbpn5x6iTFvEB8e6YnmzQktxK3CJaveWUDqABrk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086461; c=relaxed/simple; bh=sgrWOcBFo9Sd2WuA0nVAH1BFjCA3yxoLh5SvhbCkwfg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=r5+C+MlGqQ7ziYq0aqFqAb/p6SoQfQeQgXq7iW9Ql2rE4gqK74GeSM7gKJDDpdixCqR4WOL2r8a1H6LU0rb87I8VXVYl9IHgm9fAmybnHfEeO6vKKX2pStoKAqd4MIqzQUz5vuYd41QtsrVa4ETlnEhbVzaB4Fn8X6TGuzDVTtM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=BoJfZX4x; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="BoJfZX4x" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086459; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JpzU2gD6nS7CuMmMhQxgVG5WsJfE9oTaObIb5LgkYdE=; b=BoJfZX4xH8TVgWPUa1M6YwDUmlnzdLSy816Ov1S1gRDIvDffBi3vox0WG0QB53P96b5D8O m9+zKNseXY5EuISo1/wHY2Vr7b2bStZzWi4tnMuSEXcTbD0KkqRFaJgPwweNmk0cjXLQCw qi3fV7CJu5IoSeQi0Ll996rgHvqUAPM= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-537-XRSRuJ3XPsakdX1MPplkiQ-1; Fri, 07 Aug 2026 03:07:34 -0400 X-MC-Unique: XRSRuJ3XPsakdX1MPplkiQ-1 X-Mimecast-MFC-AGG-ID: XRSRuJ3XPsakdX1MPplkiQ_1786086453 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6C9451956057; Fri, 7 Aug 2026 07:07:33 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C12A21956094; Fri, 7 Aug 2026 07:07:30 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Giovanni Cabiddu Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org, qat-linux@intel.com Subject: [PATCH v4 08/10] crypto: qat - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx) Date: Fri, 7 Aug 2026 09:06:35 +0200 Message-ID: <20260807070651.228713-9-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth A recent patch by Giovanni Cabiddu already added a memzero_explicit() for the crypto_aes_ctx in the qat_alg_xts_reverse_key() function, but since we introduced __cleanup(aes_zeroize_ctx) markers in previous commits in many spots of the code already, let's use it here now, too, to have the same code pattern everywhere. Cc: Giovanni Cabiddu Signed-off-by: Thomas Huth --- drivers/crypto/intel/qat/qat_common/qat_algs.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/crypto/intel/qat/qat_common/qat_algs.c b/drivers/crypt= o/intel/qat/qat_common/qat_algs.c index 91663805d9e60..cb669fb661625 100644 --- a/drivers/crypto/intel/qat/qat_common/qat_algs.c +++ b/drivers/crypto/intel/qat/qat_common/qat_algs.c @@ -388,7 +388,7 @@ static void qat_alg_skcipher_init_enc(struct qat_alg_sk= cipher_ctx *ctx, static void qat_alg_xts_reverse_key(const u8 *key_forward, unsigned int ke= ylen, u8 *key_reverse) { - struct crypto_aes_ctx aes_expanded; + struct crypto_aes_ctx aes_expanded __cleanup(aes_zeroize_ctx); int nrounds; u8 *key; =20 @@ -405,7 +405,6 @@ static void qat_alg_xts_reverse_key(const u8 *key_forwa= rd, unsigned int keylen, memcpy(key_reverse + AES_BLOCK_SIZE, key - AES_BLOCK_SIZE, AES_BLOCK_SIZE); } - memzero_explicit(&aes_expanded, sizeof(aes_expanded)); } =20 static void qat_alg_skcipher_init_dec(struct qat_alg_skcipher_ctx *ctx, --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B8FE13A9D9F for ; Fri, 7 Aug 2026 07:07:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086467; cv=none; b=MF98KyKD+yZz+cJwY80pCBr0UHPNT3G51krKKlDOs854yPfrz8ck53ghXSzlmzmOPLhjbGv6qeecSof0lIdlLZzp/H8Tc5GvxeM4C1OOertfD+NHrx11X7+2GDHOw52A8hnRPZZQOnbwV3X0B4kE5AzFGGTkYfyMiRV2mFozvP4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086467; c=relaxed/simple; bh=F9GujSQevTps620iz5oy1DgxTU+gjz6ekhGD5dTuULw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=S35fxsXIc5Dea8JkX3sjgAGNgHHBS6tmrwZtweHPWeFyjX/asKtU7c5in9JJaVbO2z9salQpzbhqlm6gFhBlT95l/yNdqJPlCW7SR9BuF97Pl2a8R2pbXoO/8crnZN5KDFNGsdDITB6Zo6QqF05XpeET2OJn74rx8FOMZbrxs2I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=fJYQVisK; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="fJYQVisK" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086464; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=oIyHmJyMzYdv73lqmdakFUzxNfZrooLWlQlqB6xyRlY=; b=fJYQVisKPtIKKSsgBFFEqdxlwv7hpeCJpd3enI36ZzkToKf2E7uQ5p+NA+hRRr/K7SWVnI uPheKYaFiq6fPQZXVqzrLbW0qV67kcm2SUvcrKsLE1ymInAiLaxgRGa6KIWkEK84/eP6by iVkvfqs3CJMK+DgRfCuioO4qwmqZh5E= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-84-i-ZIHYNJNMGEys58Q3UdQQ-1; Fri, 07 Aug 2026 03:07:38 -0400 X-MC-Unique: i-ZIHYNJNMGEys58Q3UdQQ-1 X-Mimecast-MFC-AGG-ID: i-ZIHYNJNMGEys58Q3UdQQ_1786086457 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 360B91956095; Fri, 7 Aug 2026 07:07:37 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 19E52195DF92; Fri, 7 Aug 2026 07:07:34 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Antoine Tenart Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org Subject: [PATCH v4 09/10] crypto: safexcel - Rework cleanup of sensitive structs in safexcel_aead_setkey Date: Fri, 7 Aug 2026 09:06:36 +0200 Message-ID: <20260807070651.228713-10-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth The crypto_authenc_keys structure only contains pointers to keys, but not the key data itself. So explicitly clearing the structure at the end of safexcel_aead_setkey() is not really necessary, see Eric's recommendation here: https://lore.kernel.org/linux-crypto/20260804185402.GD2904385@google.com/ On the other hand, the crypto_aes_ctx might contain sensitive information, so this structure should be cleaned up at the end instead. Do this now via the new __cleanup(aes_zeroize_ctx) marker. Since __cleanup() and gotos should not be mixed in the same function, replace the gotos with early return statements, which is fine now that we dropped the memzero_explicit(&keys, sizeof(keys)) at the end. Suggested-by: Eric Biggers Signed-off-by: Thomas Huth Reviewed-by: Antoine Tenart --- .../crypto/inside-secure/safexcel_cipher.c | 27 ++++++++----------- 1 file changed, 11 insertions(+), 16 deletions(-) diff --git a/drivers/crypto/inside-secure/safexcel_cipher.c b/drivers/crypt= o/inside-secure/safexcel_cipher.c index a8349b684693e..c331d81ac8a2d 100644 --- a/drivers/crypto/inside-secure/safexcel_cipher.c +++ b/drivers/crypto/inside-secure/safexcel_cipher.c @@ -407,17 +407,17 @@ static int safexcel_aead_setkey(struct crypto_aead *c= tfm, const u8 *key, struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; struct crypto_authenc_keys keys; - struct crypto_aes_ctx aes; - int err =3D -EINVAL, i; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); + int err, i; const char *alg; =20 if (unlikely(crypto_authenc_extractkeys(&keys, key, len))) - goto badkey; + return -EINVAL; =20 if (ctx->mode =3D=3D CONTEXT_CONTROL_CRYPTO_MODE_CTR_LOAD) { /* Must have at least space for the nonce here */ if (unlikely(keys.enckeylen < CTR_RFC3686_NONCE_SIZE)) - goto badkey; + return -EINVAL; /* last 4 bytes of key are the nonce! */ ctx->nonce =3D *(u32 *)(keys.enckey + keys.enckeylen - CTR_RFC3686_NONCE_SIZE); @@ -430,25 +430,25 @@ static int safexcel_aead_setkey(struct crypto_aead *c= tfm, const u8 *key, case SAFEXCEL_DES: err =3D verify_aead_des_key(ctfm, keys.enckey, keys.enckeylen); if (unlikely(err)) - goto badkey; + return err; break; case SAFEXCEL_3DES: err =3D verify_aead_des3_key(ctfm, keys.enckey, keys.enckeylen); if (unlikely(err)) - goto badkey; + return err; break; case SAFEXCEL_AES: err =3D aes_expandkey(&aes, keys.enckey, keys.enckeylen); if (unlikely(err)) - goto badkey; + return err; break; case SAFEXCEL_SM4: if (unlikely(keys.enckeylen !=3D SM4_KEY_SIZE)) - goto badkey; + return -EINVAL; break; default: dev_err(priv->dev, "aead: unsupported cipher algorithm\n"); - goto badkey; + return -EINVAL; } =20 if (priv->flags & EIP197_TRC_CACHE && ctx->base.ctxr_dma) { @@ -486,24 +486,19 @@ static int safexcel_aead_setkey(struct crypto_aead *c= tfm, const u8 *key, break; default: dev_err(priv->dev, "aead: unsupported hash algorithm\n"); - goto badkey; + return -EINVAL; } =20 if (safexcel_hmac_setkey(&ctx->base, keys.authkey, keys.authkeylen, alg, ctx->state_sz)) - goto badkey; + return -EINVAL; =20 /* Now copy the keys into the context */ for (i =3D 0; i < keys.enckeylen / sizeof(u32); i++) ctx->key[i] =3D cpu_to_le32(((u32 *)keys.enckey)[i]); ctx->key_len =3D keys.enckeylen; =20 - memzero_explicit(&keys, sizeof(keys)); return 0; - -badkey: - memzero_explicit(&keys, sizeof(keys)); - return err; } =20 static int safexcel_context_control(struct safexcel_cipher_ctx *ctx, --=20 2.55.0 From nobody Tue Sep 29 13:18:56 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF1073AE6E6 for ; Fri, 7 Aug 2026 07:07:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086471; cv=none; b=lhH8Y9mExfG0xsgKIHkolmLPjmzuM3YWSGZs+8njxwHMpZhYJuEAqmdRWtwdBCgJbSskbjLNV2nzAF4pT+fNvyqiwNudkQ9aS5CYxRs574J9A7iNOXm4kW+/CkInY7l8PwC6A09ImySbZPFhCs6K7CuD2okmbWhtxA077CpQQI0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786086471; c=relaxed/simple; bh=qaIAfsiAYVelb8ir4pJGXETIHK/Ms2Y2sK1ev3Z67YI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pD/twUQvp2x5ogT8638TbfEnc2Sdpc5ORf9T7lfHGPcQ5RVhoR4K1fDqwJpN9c2Vj2OPIPJ70b67st4XagFEjbM8a3E3HX/oSwYJndKCeOVo2tEvmMLZf250NYJp7vce93P+2X/LID53F1vNqVIGO6lR7VxaXd9lsz5vwm0KF78= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=eodPsZUR; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="eodPsZUR" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786086468; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ys+EVzugstWp0eJuLjZlXzo7HqH8hJNda9tOTt9y8Qw=; b=eodPsZURzhN4dioABav4PKn2mVd2c1SHJhGe9FjN8gXIVQ8Fw7B2qEJ6G+vIpj0M3JzqgR bO9irgu6T1ttU0jUXfP+ttTlunIVvPVB30lO0lFW3Z9oG5tGx57Hoak6IkeHcFmF6rqDJ4 XBBssKeIk4bU1uo3PAPMUQgNBwdHx8Q= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-463-73bp8dHcML6W9_K9DOL0ug-1; Fri, 07 Aug 2026 03:07:45 -0400 X-MC-Unique: 73bp8dHcML6W9_K9DOL0ug-1 X-Mimecast-MFC-AGG-ID: 73bp8dHcML6W9_K9DOL0ug_1786086461 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7EB431800149; Fri, 7 Aug 2026 07:07:41 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2E2A51956094; Fri, 7 Aug 2026 07:07:38 +0000 (UTC) From: Thomas Huth To: Herbert Xu , "David S. Miller" , Antoine Tenart Cc: linux-crypto@vger.kernel.org, Eric Biggers , linux-kernel@vger.kernel.org Subject: [PATCH v4 10/10] crypto: safexcel - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx) Date: Fri, 7 Aug 2026 09:06:37 +0200 Message-ID: <20260807070651.228713-11-thuth@redhat.com> In-Reply-To: <20260807070651.228713-1-thuth@redhat.com> References: <20260807070651.228713-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" From: Thomas Huth The code clears the crypto_aes_ctx in most cases already with memzero_explicit(), but safexcel_skcipher_aesxts_setkey() runs aes_expandkey() twice, and in case the second call fails, the context from the first call is leaked. To fix this issue and to avoid future similar problems, let's use the new __cleanup(aes_zeroize_ctx) mechanism to make sure that we always clear the crypto_aes_ctx in all cases. Acked-by: Antoine Tenart Signed-off-by: Thomas Huth --- drivers/crypto/inside-secure/safexcel_cipher.c | 13 ++++--------- drivers/crypto/inside-secure/safexcel_hash.c | 3 +-- 2 files changed, 5 insertions(+), 11 deletions(-) diff --git a/drivers/crypto/inside-secure/safexcel_cipher.c b/drivers/crypt= o/inside-secure/safexcel_cipher.c index c331d81ac8a2d..54ab08aea7536 100644 --- a/drivers/crypto/inside-secure/safexcel_cipher.c +++ b/drivers/crypto/inside-secure/safexcel_cipher.c @@ -375,7 +375,7 @@ static int safexcel_skcipher_aes_setkey(struct crypto_s= kcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); @@ -396,7 +396,6 @@ static int safexcel_skcipher_aes_setkey(struct crypto_s= kcipher *ctfm, =20 ctx->key_len =3D len; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -1357,7 +1356,7 @@ static int safexcel_skcipher_aesctr_setkey(struct cry= pto_skcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; unsigned int keylen; =20 @@ -1383,7 +1382,6 @@ static int safexcel_skcipher_aesctr_setkey(struct cry= pto_skcipher *ctfm, =20 ctx->key_len =3D keylen; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -2537,7 +2535,7 @@ static int safexcel_skcipher_aesxts_setkey(struct cry= pto_skcipher *ctfm, struct crypto_tfm *tfm =3D crypto_skcipher_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; unsigned int keylen; =20 @@ -2585,7 +2583,6 @@ static int safexcel_skcipher_aesxts_setkey(struct cry= pto_skcipher *ctfm, =20 ctx->key_len =3D keylen << 1; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 @@ -2751,12 +2748,11 @@ static int safexcel_aead_ccm_setkey(struct crypto_a= ead *ctfm, const u8 *key, struct crypto_tfm *tfm =3D crypto_aead_tfm(ctfm); struct safexcel_cipher_ctx *ctx =3D crypto_tfm_ctx(tfm); struct safexcel_crypto_priv *priv =3D ctx->base.priv; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); if (ret) { - memzero_explicit(&aes, sizeof(aes)); return ret; } =20 @@ -2785,7 +2781,6 @@ static int safexcel_aead_ccm_setkey(struct crypto_aea= d *ctfm, const u8 *key, else ctx->hash_alg =3D CONTEXT_CONTROL_CRYPTO_ALG_XCBC128; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 diff --git a/drivers/crypto/inside-secure/safexcel_hash.c b/drivers/crypto/= inside-secure/safexcel_hash.c index 3402e570d045c..20c17eb09495e 100644 --- a/drivers/crypto/inside-secure/safexcel_hash.c +++ b/drivers/crypto/inside-secure/safexcel_hash.c @@ -1905,7 +1905,7 @@ static int safexcel_cbcmac_setkey(struct crypto_ahash= *tfm, const u8 *key, unsigned int len) { struct safexcel_ahash_ctx *ctx =3D crypto_tfm_ctx(crypto_ahash_tfm(tfm)); - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_zeroize_ctx); int ret, i; =20 ret =3D aes_expandkey(&aes, key, len); @@ -1928,7 +1928,6 @@ static int safexcel_cbcmac_setkey(struct crypto_ahash= *tfm, const u8 *key, } ctx->cbcmac =3D true; =20 - memzero_explicit(&aes, sizeof(aes)); return 0; } =20 --=20 2.55.0