mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final()
@ 2026-10-06  8:34 Eric Biggers
  2026-10-06 10:10 ` Ard Biesheuvel
  2026-10-06 12:25 ` Eric Biggers
  0 siblings, 2 replies; 3+ messages in thread
From: Eric Biggers @ 2026-10-06  8:34 UTC (permalink / raw)
  To: linux-crypto
  Cc: linux-kernel, Ard Biesheuvel, Jason A . Donenfeld, Herbert Xu,
	Eric Biggers, stable, Sashiko

Use memzero_explicit() instead of a plain struct assignment to guarantee
zeroization of the 'struct poly1305_desc_ctx'.

Note that dead store elimination was only theoretically possible with
link-time optimization here.  But it's still worth fixing.

Fixes: a1d93064094c ("crypto: poly1305 - expose init/update/final library interface")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/bug/linux-c3a6bd76-f6ab-4203-892a-cd06f7aa0c34
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
---
 lib/crypto/poly1305.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/crypto/poly1305.c b/lib/crypto/poly1305.c
index f313ccc4b4dd2..048c7afe86138 100644
--- a/lib/crypto/poly1305.c
+++ b/lib/crypto/poly1305.c
@@ -78,7 +78,7 @@ void poly1305_final(struct poly1305_desc_ctx *desc, u8 *dst)
 	}
 
 	poly1305_emit(&desc->state.h, dst, desc->s);
-	*desc = (struct poly1305_desc_ctx){};
+	memzero_explicit(desc, sizeof(*desc));
 }
 EXPORT_SYMBOL(poly1305_final);
 

base-commit: 6a50ce0af5c91fd665d65d357af8ae55db1df7d0
-- 
2.56.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final()
  2026-10-06  8:34 [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final() Eric Biggers
@ 2026-10-06 10:10 ` Ard Biesheuvel
  2026-10-06 12:25 ` Eric Biggers
  1 sibling, 0 replies; 3+ messages in thread
From: Ard Biesheuvel @ 2026-10-06 10:10 UTC (permalink / raw)
  To: Eric Biggers, linux-crypto
  Cc: linux-kernel, Jason A . Donenfeld, Herbert Xu, stable, Sashiko


On Tue, 6 Oct 2026, at 10:34, Eric Biggers wrote:
> Use memzero_explicit() instead of a plain struct assignment to guarantee
> zeroization of the 'struct poly1305_desc_ctx'.
>
> Note that dead store elimination was only theoretically possible with
> link-time optimization here.  But it's still worth fixing.
>
> Fixes: a1d93064094c ("crypto: poly1305 - expose init/update/final 
> library interface")
> Cc: stable@vger.kernel.org
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: 
> https://sashiko.dev/#/bug/linux-c3a6bd76-f6ab-4203-892a-cd06f7aa0c34
> Signed-off-by: Eric Biggers <ebiggers@kernel.org>
> ---
>  lib/crypto/poly1305.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>

Reviewed-by: Ard Biesheuvel <ardb@kernel.org>

> diff --git a/lib/crypto/poly1305.c b/lib/crypto/poly1305.c
> index f313ccc4b4dd2..048c7afe86138 100644
> --- a/lib/crypto/poly1305.c
> +++ b/lib/crypto/poly1305.c
> @@ -78,7 +78,7 @@ void poly1305_final(struct poly1305_desc_ctx *desc, u8 *dst)
>  	}
> 
>  	poly1305_emit(&desc->state.h, dst, desc->s);
> -	*desc = (struct poly1305_desc_ctx){};
> +	memzero_explicit(desc, sizeof(*desc));
>  }
>  EXPORT_SYMBOL(poly1305_final);
> 
>
> base-commit: 6a50ce0af5c91fd665d65d357af8ae55db1df7d0
> -- 
> 2.56.0

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final()
  2026-10-06  8:34 [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final() Eric Biggers
  2026-10-06 10:10 ` Ard Biesheuvel
@ 2026-10-06 12:25 ` Eric Biggers
  1 sibling, 0 replies; 3+ messages in thread
From: Eric Biggers @ 2026-10-06 12:25 UTC (permalink / raw)
  To: linux-crypto
  Cc: linux-kernel, Ard Biesheuvel, Jason A . Donenfeld, Herbert Xu,
	stable, Sashiko

On Tue, Oct 06, 2026 at 10:34:32AM +0200, Eric Biggers wrote:
> Use memzero_explicit() instead of a plain struct assignment to guarantee
> zeroization of the 'struct poly1305_desc_ctx'.
> 
> Note that dead store elimination was only theoretically possible with
> link-time optimization here.  But it's still worth fixing.
> 
> Fixes: a1d93064094c ("crypto: poly1305 - expose init/update/final library interface")
> Cc: stable@vger.kernel.org
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://sashiko.dev/#/bug/linux-c3a6bd76-f6ab-4203-892a-cd06f7aa0c34
> Signed-off-by: Eric Biggers <ebiggers@kernel.org>
> ---
>  lib/crypto/poly1305.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Applied to https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git/log/?h=libcrypto-next

- Eric

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-06 12:25 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06  8:34 [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final() Eric Biggers
2026-10-06 10:10 ` Ard Biesheuvel
2026-10-06 12:25 ` Eric Biggers

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®