[PATCH 0/4] CRASH_ZEROIZE: Wipe secrets before kdump
Jan Sebastian Götte <[email protected]> Fri, 31 Jul 2026 18:27:35 +0200
| Newsgroups | org.kernel.vger.keyrings,org.infradead.lists.kexec,org.kernel.vger.linux-devicetree,org.kernel.vger.linux-integrity,org.kernel.vger.linux-kernel,org.kernel.vger.linux-security-module,org.kvack.linux-mm |
|---|---|
| Message-ID | <[email protected]> |
I'm using linux on an embedded target in a Hardware Security Module-like application. One requirement is that I want the system to be able to quickly erase its memory when it detects physical tampering. I'm approaching that by using kdump to load into a small payload that instead of dumping RAM, erases RAM from start to end. However, writing all of RAM, especially on an embedded target, is rather slow. For this reason, I propose the mechanism in this patch series: Add CONFIG_CRASH_ZEROIZE (default off), which when enabled makes various subsystems handling secret data do a quick, targeted wipe of these secrets before kdump. This behavior might also be interesting in cases where you run a normal kdump kernel but you still want to keep things like fde crypto keys out of these dumps. CONFIG_CRASH_ZEROIZE is a best effort, defense in depth solution. There are circumstances, such as when a panic is triggered after memory corruption, or when a panic interrupts some operation that mutates data structures under locks, when the kernel cannot safely wipe some memory areas. The handlers proposed in this series will just print a warning and skip the affected areas in this case. This series introduces two handlers as a starting point: One for kernel keyrings, and one for secretmem. Future places where such handlers could be added would be for example drivers for crypto accelerators. The patch series applies on top of linux-next but should work on 7.0.0, too. I've tested the patches on a Arduino uno Q (Qualcomm QRB2210) embedded target. Jan Sebastian Götte (4): of/kexec: fix typo in comment (usable-memory-range) kexec: add CRASH_ZEROIZE to wipe secrets before kdump mm/secretmem: zeroize secret pages before kdump security/keys: zeroize key payloads before kdump drivers/of/kexec.c | 2 +- include/linux/crash_core.h | 5 +++ include/linux/key-type.h | 9 ++++ kernel/Kconfig.kexec | 8 ++++ kernel/crash_core.c | 18 ++++++++ mm/secretmem.c | 50 +++++++++++++++++++++++ security/keys/big_key.c | 15 +++++++ security/keys/encrypted-keys/encrypted.c | 12 ++++++ security/keys/key.c | 44 ++++++++++++++++++++ security/keys/trusted-keys/trusted_core.c | 14 +++++++ security/keys/user_defined.c | 11 +++++ 11 files changed, 187 insertions(+), 1 deletion(-) -- 2.53.0