[PATCH v2 0/2] PAES - Fix rc handling at skcipher_walk_done

Harald Freudenberger <[email protected]> Wed, 5 Aug 2026 17:54:56 +0200
Newsgroups org.kernel.vger.linux-crypto,org.kernel.vger.linux-s390
Message-ID <[email protected]>
All the 4 PAES cipher processing loops were not checking the return
value of skcipher_walk_done() immediately after calling it. This could
lead to error masking when both the walk operation failed and a
subsequent key conversion was needed (k < n condition).

Add immediate error checks after skcipher_walk_done() in all main
processing loops (ECB, CBC, CTR, XTS modes) to ensure walk errors are
properly propagated and not masked by subsequent operations.

Patch #2 deals with a not scrubbed temp buffer.

Changelog:

v1: initial patch
v2: - Sashiko found that now there is a possibility to double
      de-allocate resources held by the walk. So another check if the
      walk has already been finalized is now part of the patch.
    - Sashiko also stumbled over a not scrubbed temp buffer with the
      PAES ctr mode implementation. So another patch added which
      scrubs this buffer.   

Harald Freudenberger (2):
  s390/crypto: Fix return code handling at skcipher_walk_done in PAES
    algorithms
  s390/crypto: Explicit scrub temp buffer in PAES ctr mode algorithm

 arch/s390/crypto/paes_s390.c | 39 ++++++++++++++++++++++++++----------
 1 file changed, 28 insertions(+), 11 deletions(-)

--
2.43.0