[PATCH v2 2/9] crypto: aspeed - clear the crypto_aes_ctx when done
Thomas Huth <[email protected]> Mon, 3 Aug 2026 11:44:21 +0200
| Newsgroups | org.ozlabs.lists.linux-aspeed,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-crypto,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
From: Thomas Huth <[email protected]> Declare the gen_aes_key with __cleanup(aes_clear_ctx) to avoid that its contents could be leaking via the stack when the function returns. And since it is only required in one branch of the if-statement there, move it to that block, too. Signed-off-by: Thomas Huth <[email protected]> --- drivers/crypto/aspeed/aspeed-hace-crypto.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/crypto/aspeed/aspeed-hace-crypto.c b/drivers/crypto/aspeed/aspeed-hace-crypto.c index fa201dae1f81b..74a4ce62fcd93 100644 --- a/drivers/crypto/aspeed/aspeed-hace-crypto.c +++ b/drivers/crypto/aspeed/aspeed-hace-crypto.c @@ -576,7 +576,6 @@ static int aspeed_aes_setkey(struct crypto_skcipher *cipher, const u8 *key, { struct aspeed_cipher_ctx *ctx = crypto_skcipher_ctx(cipher); struct aspeed_hace_dev *hace_dev = ctx->hace_dev; - struct crypto_aes_ctx gen_aes_key; CIPHER_DBG(hace_dev, "keylen: %d bits\n", (keylen * 8)); @@ -585,9 +584,9 @@ static int aspeed_aes_setkey(struct crypto_skcipher *cipher, const u8 *key, return -EINVAL; if (ctx->hace_dev->version == AST2500_VERSION) { + struct crypto_aes_ctx gen_aes_key __cleanup(aes_clear_ctx); aes_expandkey(&gen_aes_key, key, keylen); memcpy(ctx->key, gen_aes_key.key_enc, AES_MAX_KEYLENGTH); - } else { memcpy(ctx->key, key, keylen); } -- 2.55.0