]> www.infradead.org Git - users/jedix/linux-maple.git/commitdiff
crypto: rng - Zero seed in crypto_rng_reset
authorHerbert Xu <herbert@gondor.apana.org.au>
Tue, 21 Apr 2015 02:46:49 +0000 (10:46 +0800)
committerJack Vogel <jack.vogel@oracle.com>
Thu, 5 Apr 2018 20:09:13 +0000 (13:09 -0700)
If we allocate a seed on behalf ot the user in crypto_rng_reset,
we must ensure that it is zeroed afterwards or the RNG may be
compromised.

Reported-by: Stephan Mueller <smueller@chronox.de>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
(cherry picked from commit b617b702da4e922277806f81c411d3051107d462)

Orabug: 27809271

Signed-off-by: John Haxby <john.haxby@oracle.com>
Reviewed-by: HÃ¥kon Bugge <haakon.bugge@oracle.com>
crypto/rng.c

index e98ce1ca527dc3e3a7a772a504a94b33cd074887..9ab8d903f72d6616672e1a55b3134d5c82beb54e 100644 (file)
@@ -85,7 +85,7 @@ int crypto_rng_reset(struct crypto_rng *tfm, const u8 *seed, unsigned int slen)
 
        err = tfm->seed(tfm, seed, slen);
 
-       kfree(buf);
+       kzfree(buf);
        return err;
 }
 EXPORT_SYMBOL_GPL(crypto_rng_reset);