[PATCH v2 3/9] crypto: inside-secure/eip93 - clear the crypto_aes_ctx when done
Thomas Huth <[email protected]> Mon, 3 Aug 2026 11:44:22 +0200
| Newsgroups | org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
From: Thomas Huth <[email protected]> Clear the crypto_aes_ctx structure via __cleanup(aes_clear_ctx) when we're done with it to avoid that key data could leak on the stack. Cc: Christian Marangi <[email protected]> Cc: Antoine Tenart <[email protected]> Signed-off-by: Thomas Huth <[email protected]> --- drivers/crypto/inside-secure/eip93/eip93-aead.c | 2 +- drivers/crypto/inside-secure/eip93/eip93-cipher.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/crypto/inside-secure/eip93/eip93-aead.c b/drivers/crypto/inside-secure/eip93/eip93-aead.c index 2bbd0af7b0e0e..8bbbf8c0b8c98 100644 --- a/drivers/crypto/inside-secure/eip93/eip93-aead.c +++ b/drivers/crypto/inside-secure/eip93/eip93-aead.c @@ -92,7 +92,7 @@ static int eip93_aead_setkey(struct crypto_aead *ctfm, const u8 *key, struct crypto_tfm *tfm = crypto_aead_tfm(ctfm); struct eip93_crypto_ctx *ctx = crypto_tfm_ctx(tfm); struct crypto_authenc_keys keys; - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_clear_ctx); struct sa_record *sa_record = ctx->sa_record; u32 nonce = 0; int ret; diff --git a/drivers/crypto/inside-secure/eip93/eip93-cipher.c b/drivers/crypto/inside-secure/eip93/eip93-cipher.c index 4dd7ab7503e85..3f9a15aa93541 100644 --- a/drivers/crypto/inside-secure/eip93/eip93-cipher.c +++ b/drivers/crypto/inside-secure/eip93/eip93-cipher.c @@ -116,7 +116,7 @@ static int eip93_skcipher_setkey(struct crypto_skcipher *ctfm, const u8 *key, } if (flags & EIP93_ALG_AES) { - struct crypto_aes_ctx aes; + struct crypto_aes_ctx aes __cleanup(aes_clear_ctx); ctx->blksize = AES_BLOCK_SIZE; ret = aes_expandkey(&aes, key, keylen); -- 2.55.0