From: Eric Biggers <ebiggers@kernel.org>
To: Mohamad Raizudeen <raizudeen.kerneldev@gmail.com>
Cc: "Jason A. Donenfeld" <Jason@zx2c4.com>,
ardb@kernel.org, skhan@linuxfoundation.org,
me@brighamcampbell.com, jkoolstra@xs4all.nl,
linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: Re: [PATCH] crypto: chacha20poly1305 - Fix missing state zeroization in xchacha decrypt
Date: Sun, 4 Oct 2026 18:52:17 +0200 [thread overview]
Message-ID: <20261004165217.GA1906@quark> (raw)
In-Reply-To: <asHGD1_z-N9k0czy@kernel>
On Sun, Oct 04, 2026 at 08:50:47AM +0530, Mohamad Raizudeen wrote:
> No, none that exist today. The only in-tree callers are the wireguard
> cookie code and the kunit test and I agree the cookie has no forward
> secrecy concerns. My only thought is that the function is
> EXPORT_SYMBOL()ed, so a future caller with a long term key would leave
> the derived subkey on the stack and since chacha20poly1305_decrypt()
> already wipes the state, having the xchacha variant do the same seemed
> like safer default.
>
> Also, Eric requested a v2 that moves the zeroization into the helper
> function for consistency with the encrypt path, so I will be sending
> that out shortly.
>
> Thanks,
> Mohamad Raizudeen
I agree: the crypto code should be compatible with callers that need the
key to be zeroized, even if none needs it right now. Otherwise it's
just way too subtle, with some functions doing it and others not.
- Eric
prev parent reply other threads:[~2026-10-04 16:52 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 6:08 Mohamad Raizudeen
2026-10-03 7:34 ` Ard Biesheuvel
2026-10-03 8:57 ` Eric Biggers
2026-10-03 9:28 ` Ard Biesheuvel
2026-10-03 16:39 ` Eric Biggers
2026-10-03 16:55 ` Mohamad Raizudeen
2026-10-03 20:22 ` Jason A. Donenfeld
2026-10-04 3:20 ` Mohamad Raizudeen
2026-10-04 16:52 ` Eric Biggers [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004165217.GA1906@quark \
--to=ebiggers@kernel.org \
--cc=Jason@zx2c4.com \
--cc=ardb@kernel.org \
--cc=jkoolstra@xs4all.nl \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=me@brighamcampbell.com \
--cc=raizudeen.kerneldev@gmail.com \
--cc=skhan@linuxfoundation.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®