Re: [PATCH v2 2/6] smb: clear the aes_cmac_key and aes_cmac_ctx when done
Namjae Jeon <[email protected]>
| Newsgroups | org.kernel.vger.linux-cifs,org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAKYAXd_VJH8dFHofy2Jfk2172vDuU+XizXQf06w0oz81F1WDdQ@mail.gmail.com> |
> diff --git a/fs/smb/client/smb2transport.c b/fs/smb/client/smb2transport.c
> index 1143ee52470a7..d23566da2ac81 100644
> --- a/fs/smb/client/smb2transport.c
> +++ b/fs/smb/client/smb2transport.c
> @@ -464,8 +464,8 @@ smb3_calc_signature(struct smb_rqst *rqst, struct TCP_Server_Info *server)
> unsigned char smb3_signature[SMB2_CMACAES_SIZE];
> struct kvec *iov = rqst->rq_iov;
> struct smb2_hdr *shdr = (struct smb2_hdr *)iov[0].iov_base;
> - struct aes_cmac_key cmac_key;
> - struct aes_cmac_ctx cmac_ctx;
> + struct aes_cmac_key cmac_key __cleanup(aes_cmac_zeroize_key);
> + struct aes_cmac_ctx cmac_ctx __cleanup(aes_cmac_zeroize_ctx);
> struct smb_rqst drqst;
> u8 key[SMB3_SIGN_KEY_SIZE];
Shouldn’t we also clear the raw key with memzero_explicit(key,
sizeof(key)) immediately after aes_cmac_preparekey() ?
rc = aes_cmac_preparekey(&cmac_key, key, SMB2_CMACAES_SIZE);
+ memzero_explicit(key, sizeof(key));
if (rc) {
cifs_server_dbg(VFS, "%s: Could not set key for cmac
aes\n", __func__);
return rc;
}