]> www.infradead.org Git - users/dwmw2/linux.git/commit
KEYS: trusted: dcp: fix improper sg use with CONFIG_VMAP_STACK=y
authorDavid Gstir <david@sigma-star.at>
Wed, 13 Nov 2024 21:27:54 +0000 (22:27 +0100)
committerJarkko Sakkinen <jarkko@kernel.org>
Tue, 21 Jan 2025 09:25:23 +0000 (11:25 +0200)
commite8d9fab39d1f87b52932646b2f1e7877aa3fc0f4
tree6a7fb188d34261e867683822e24bd1f6d9afd884
parent5f56d41a21b6d17b59525958a57feffe597b7de5
KEYS: trusted: dcp: fix improper sg use with CONFIG_VMAP_STACK=y

With vmalloc stack addresses enabled (CONFIG_VMAP_STACK=y) DCP trusted
keys can crash during en- and decryption of the blob encryption key via
the DCP crypto driver. This is caused by improperly using sg_init_one()
with vmalloc'd stack buffers (plain_key_blob).

Fix this by always using kmalloc() for buffers we give to the DCP crypto
driver.

Cc: stable@vger.kernel.org # v6.10+
Fixes: 0e28bf61a5f9 ("KEYS: trusted: dcp: fix leak of blob encryption key")
Signed-off-by: David Gstir <david@sigma-star.at>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
security/keys/trusted-keys/trusted_dcp.c