Re: [PATCH v4 2/3] s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm
Holger Dengler <[email protected]>
| Newsgroups | org.kernel.vger.linux-crypto,org.kernel.vger.linux-s390 |
|---|---|
| Message-ID | <[email protected]> |
On 8/14/26 14:37, Harald Freudenberger wrote:
> In function ctr_aes_crypt() there is a buffer used to process
> remaining bytes < AES_BLOCK_SIZE. This buffer was not scrubbed and
> thus could lead to expose of unwanted data. When the buffer is used
> explicitly scrub it at the end of the code block to avoid exposure of
> maybe sensitive data.
>
> In a similar way the function gcm_aes_crypt() hat an error path where
> the CPACF param block was not scrubbed. Instead of return early now
> these error paths go to end of function where explicit scrubbing is
> done. Similar with the buffers which are part of the gcm_sg_walk
> structs from the variables gw_in and gw_out.
>
> Fixes: d07f951903fa ("crypto: s390/aes - Fix buffer overread in CTR mode")
> Signed-off-by: Harald Freudenberger <[email protected]>
> Cc: [email protected] # 6.8+
Reviewed-by: Holger Dengler <[email protected]>
--
Mit freundlichen Grüßen / Kind regards
Holger Dengler