From nobody Tue Sep 29 04:09:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D48B238DC59 for ; Wed, 12 Aug 2026 16:33:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786552441; cv=none; b=NLqCSgN0GofDeJpYeAXHGudG/D/bxLHh9aYRi74L/QEr4h9RRd2BsMWzMftruGUyJB0v8/42JA17lE5dgJ4lsQW+VaZOqlJZJNPh5TtHvasZmrf0iyao4ad1fdASLvrfTuup+LOTdcpkr6dCNE4n+diZvLRYbLZc3K0qg1puPWU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786552441; c=relaxed/simple; bh=bxV3nNhujFCo/j0BBm3SWAO2vxLMMMF8yj/eOkRK/js=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gpjz1QbVR3Q/LPfW1paVpKH1CR10U6g0Eunm6gLscWUs1bOTOmajc6RZlzObfJ46n2+KHRsftK2K6SNQHylt4/58khy6xpepma3iJld0ZZRuO1+rr6ki8ccFUHlAcYKAeslezcWxUyWZU2ENopXKNJm4+o/fjOzlh5U4mY2LMdg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Isvxm/O0; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Isvxm/O0" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786552438; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UGIFpIHoV2cEX83WsLrSc51nn4LgmfnamxTBBgPZei0=; b=Isvxm/O0D0E+ruE2itc8fUnX/CavZPw4ZQVEsHLXYyMqZUokru5K0fX2ODmfDcgyAEHMkg TABcG1IYJIYqLNdYP1E+j8t9TBTvRAsmXRkJGG+0TsazXEvrGLq4nXV6nrXG7A3d3gcSX7 Dm0WCXxJWE5TytQOJcgAOvjkxHJT8QA= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-587-xyxIukceP8Sy5-O0EseSwA-1; Wed, 12 Aug 2026 12:33:52 -0400 X-MC-Unique: xyxIukceP8Sy5-O0EseSwA-1 X-Mimecast-MFC-AGG-ID: xyxIukceP8Sy5-O0EseSwA_1786552430 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8563B1956042; Wed, 12 Aug 2026 16:33:49 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 116733002D26; Wed, 12 Aug 2026 16:33:43 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel Cc: Herbert Xu , "David S. Miller" , James Bottomley , Jarkko Sakkinen , Mimi Zohar , David Howells , Paul Moore , James Morris , "Serge E. Hallyn" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module@vger.kernel.org Subject: [PATCH 1/3] crypto: Provide a wrapper for zeroizing hmac_sha1_ctx Date: Wed, 12 Aug 2026 18:33:34 +0200 Message-ID: <20260812163336.3103835-2-thuth@redhat.com> In-Reply-To: <20260812163336.3103835-1-thuth@redhat.com> References: <20260812163336.3103835-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Some kernel code needs to zeroize their local hmac_sha1_ctx structures after use to avoid leaking sensitive material on the stack. Provide an hmac_sha1_zeroize_ctx() helper that can be used with __cleanup() to automatically zeroize the context when it goes out of scope. Signed-off-by: Thomas Huth Reviewed-by: Jarkko Sakkinen --- include/crypto/sha1.h | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/include/crypto/sha1.h b/include/crypto/sha1.h index 4d973e016cd69..888dfc62e1c65 100644 --- a/include/crypto/sha1.h +++ b/include/crypto/sha1.h @@ -7,6 +7,7 @@ #define _CRYPTO_SHA1_H =20 #include +#include =20 #define SHA1_DIGEST_SIZE 20 #define SHA1_BLOCK_SIZE 64 @@ -106,6 +107,22 @@ struct hmac_sha1_ctx { struct sha1_block_state ostate; }; =20 +/** + * hmac_sha1_zeroize_ctx() - Zeroize a hmac_sha1_ctx structure + * @ctx: The location of the context that should be zeroized + * + * This function explicitly fills the hmac_sha1_ctx with zeroes. For + * example, it can be used with __cleanup() for local hmac_sha1_ctx + * structures on the stack, so that their content is not leaked via the + * stack when the context is left. Note: This is only required when not + * using hmac_sha1_final() that already zeroizes the structure at the + * end. + */ +static inline void hmac_sha1_zeroize_ctx(struct hmac_sha1_ctx *ctx) +{ + memzero_explicit(ctx, sizeof(*ctx)); +} + /** * hmac_sha1_preparekey() - Prepare a key for HMAC-SHA1 * @key: (output) the key structure to initialize --=20 2.55.0 From nobody Tue Sep 29 04:09:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3D3B4476077 for ; Wed, 12 Aug 2026 16:34:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786552447; cv=none; b=I4hVFcpIYLXjTF7Oq9Gra1/Tm16wR/2CdmeKlWO4dybU/PUWoQRsH4R3Sd9/dAN5X+lD/c6sih6ZnQnh4NiAA2M1zSBnfkp2jpMej3GW81yCrchyFTgRYbucnXLveVYlvYlBqgLU7+0e40w3MrE2nOazXc22A4S2lMSx+51ofBs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786552447; c=relaxed/simple; bh=H0AsNw6nyb/BtVnYK60V39hmdcgkIq5e7NKdNvUULCA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mWsEEQtTCLkqBsovD/oQ5JN9sG/RGLRpX6Ow1fuZyx/tikGMK5UOCrz/YkrU6I6RnwNQQfYL8Cq5sORA/DFukU92gvdEBH7g6AkNmnf/9CNRK01hHVFDl1MRasLGWMiBSnycTupEPetruuJkIKcYx3a4oEmwpJ4xu3ZK1uVZ8VI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=VZVK3q6b; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="VZVK3q6b" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786552440; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Iy7j/qc0bwgXcBR+rs01Cp3y9nQB0NyqAakXgL7RNv4=; b=VZVK3q6bKvm7Z+C/PSlLsSwAlZojVo5dhMB9xAk6YMHTLoJ8AqRd5kuJJYxutQJqCVlLBL 8c7K6owV0GmBaC2IYZhGFXeFIkNknJTF4NS24ZxzDVjZcasalpW0a8FJXDNiOsrSjUZaUa ckMpdW9axe2uqrY+jKgU8aRTN2BTt4U= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-625-qJhN_oKbOPKXR9IOzvP6vg-1; Wed, 12 Aug 2026 12:33:58 -0400 X-MC-Unique: qJhN_oKbOPKXR9IOzvP6vg-1 X-Mimecast-MFC-AGG-ID: qJhN_oKbOPKXR9IOzvP6vg_1786552436 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id DDE261956048; Wed, 12 Aug 2026 16:33:55 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EE8FF3002D29; Wed, 12 Aug 2026 16:33:49 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel Cc: Herbert Xu , "David S. Miller" , James Bottomley , Jarkko Sakkinen , Mimi Zohar , David Howells , Paul Moore , James Morris , "Serge E. Hallyn" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module@vger.kernel.org Subject: [PATCH 2/3] security: keys: trusted: always clear the hmac_sha1_ctx before returning Date: Wed, 12 Aug 2026 18:33:35 +0200 Message-ID: <20260812163336.3103835-3-thuth@redhat.com> In-Reply-To: <20260812163336.3103835-1-thuth@redhat.com> References: <20260812163336.3103835-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth Clear the hmac_sha1_ctx structure via __cleanup(hmac_sha1_zeroize_ctx) to make sure that the function cannot leak any sensitive data on the stack in case we return without hmac_sha1_final() here. Signed-off-by: Thomas Huth Reviewed-by: Jarkko Sakkinen --- security/keys/trusted-keys/trusted_tpm1.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/security/keys/trusted-keys/trusted_tpm1.c b/security/keys/trus= ted-keys/trusted_tpm1.c index 13513819991e7..90536ae53d4a8 100644 --- a/security/keys/trusted-keys/trusted_tpm1.c +++ b/security/keys/trusted-keys/trusted_tpm1.c @@ -102,7 +102,7 @@ static inline void dump_tpm_buf(unsigned char *buf) static int TSS_rawhmac(unsigned char *digest, const unsigned char *key, unsigned int keylen, ...) { - struct hmac_sha1_ctx hmac_ctx; + struct hmac_sha1_ctx hmac_ctx __cleanup(hmac_sha1_zeroize_ctx); va_list argp; unsigned int dlen; unsigned char *data; --=20 2.55.0 From nobody Tue Sep 29 04:09:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 37AFA42CB14 for ; Wed, 12 Aug 2026 16:34:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786552452; cv=none; b=RZ3S7VP75K9B48OBUKN1hxMbFNOlTj/iZRVnat2s67QTpFetNFaT2C53v8Dz4JzadzbVXEvc7IKloF3CU6UWqZ9zMqiIXNFxvq1sD2AYh5t8ocda6tk0Bk4PP7udWsDnsjbdrTLp0M1+CG3ZaVmdOC7CLc2e3RYoy/lXWfImgfc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786552452; c=relaxed/simple; bh=+2zRxSvjAmqwYOE+tKwr1WSnbMWmNOH7W2evqTcz3wE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gjZkyuGxvIlwHs+ofjsh5nKMiYQBXBnSM4RhP+zNaHwn/ag02rMJVACVfoXhOeSD5wD/0wy5a6NB0YWYn3g8fh5eCiumdGkLJoxtLlbzmBFntzMDoZOXf2/wHI6CbodDQzzgBN7rZPiONRX8hNdueasv3n09TfwLRlsZP3Cxids= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=gjH57X5F; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="gjH57X5F" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786552450; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JpTxCCo1JlTQTpMq2MklUewzzbiQjhVKEixoMx1SLYE=; b=gjH57X5Fbtr20nRSCqBhn5K/df0+ciLR6mawO7I8fzYV85GZRBRCVDBzLo8q3a79MmTHe0 dCy68SWcIaT+pzQtCRZ4lV1w5Zo4gLuU7JUrCPqhVxoFAyL1ADx/3mbvmRIiEGta/6yPsW 1cC4OTnJF9rJ6IoA6NKzwvb2+2kCEkM= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-355-rnie3BrMNuqh1rYf3ZMijw-1; Wed, 12 Aug 2026 12:34:04 -0400 X-MC-Unique: rnie3BrMNuqh1rYf3ZMijw-1 X-Mimecast-MFC-AGG-ID: rnie3BrMNuqh1rYf3ZMijw_1786552442 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 57089180028A; Wed, 12 Aug 2026 16:34:02 +0000 (UTC) Received: from thuth-p1g4.redhat.corp (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 4E4443002D30; Wed, 12 Aug 2026 16:33:56 +0000 (UTC) From: Thomas Huth To: Eric Biggers , "Jason A. Donenfeld" , Ard Biesheuvel Cc: Herbert Xu , "David S. Miller" , James Bottomley , Jarkko Sakkinen , Mimi Zohar , David Howells , Paul Moore , James Morris , "Serge E. Hallyn" , linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-security-module@vger.kernel.org Subject: [PATCH 3/3] lib/crypto: sha1: Use hmac_sha1_zeroize_ctx() instead of memzero_explicit() Date: Wed, 12 Aug 2026 18:33:36 +0200 Message-ID: <20260812163336.3103835-4-thuth@redhat.com> In-Reply-To: <20260812163336.3103835-1-thuth@redhat.com> References: <20260812163336.3103835-1-thuth@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" From: Thomas Huth It's only cosmetics, but since we have the new hmac_sha1_zeroize_ctx() function anyway, we can also use it here. Signed-off-by: Thomas Huth Reviewed-by: Jarkko Sakkinen --- lib/crypto/sha1.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/crypto/sha1.c b/lib/crypto/sha1.c index b687b89d97cb4..c4361ef77166e 100644 --- a/lib/crypto/sha1.c +++ b/lib/crypto/sha1.c @@ -275,7 +275,7 @@ void hmac_sha1_final(struct hmac_sha1_ctx *ctx, u8 out[= SHA1_DIGEST_SIZE]) for (size_t i =3D 0; i < SHA1_DIGEST_SIZE; i +=3D 4) put_unaligned_be32(ctx->ostate.h[i / 4], out + i); =20 - memzero_explicit(ctx, sizeof(*ctx)); + hmac_sha1_zeroize_ctx(ctx); } EXPORT_SYMBOL_GPL(hmac_sha1_final); =20 --=20 2.55.0