if (crypto_shash_setkey(tfm, &asoc_key->data[0], asoc_key->len))
                goto free;
 
-       {
-               SHASH_DESC_ON_STACK(desc, tfm);
-
-               desc->tfm = tfm;
-               crypto_shash_digest(desc, (u8 *)auth,
-                                   end - (unsigned char *)auth, digest);
-               shash_desc_zero(desc);
-       }
+       crypto_shash_tfm_digest(tfm, (u8 *)auth, end - (unsigned char *)auth,
+                               digest);
 
 free:
        if (free_key)
 
               ntohs(init_chunk->chunk_hdr->length), raw_addrs, addrs_len);
 
        if (sctp_sk(ep->base.sk)->hmac) {
-               SHASH_DESC_ON_STACK(desc, sctp_sk(ep->base.sk)->hmac);
+               struct crypto_shash *tfm = sctp_sk(ep->base.sk)->hmac;
                int err;
 
                /* Sign the message.  */
-               desc->tfm = sctp_sk(ep->base.sk)->hmac;
-
-               err = crypto_shash_setkey(desc->tfm, ep->secret_key,
+               err = crypto_shash_setkey(tfm, ep->secret_key,
                                          sizeof(ep->secret_key)) ?:
-                     crypto_shash_digest(desc, (u8 *)&cookie->c, bodysize,
-                                         cookie->signature);
-               shash_desc_zero(desc);
+                     crypto_shash_tfm_digest(tfm, (u8 *)&cookie->c, bodysize,
+                                             cookie->signature);
                if (err)
                        goto free_cookie;
        }
 
        /* Check the signature.  */
        {
-               SHASH_DESC_ON_STACK(desc, sctp_sk(ep->base.sk)->hmac);
+               struct crypto_shash *tfm = sctp_sk(ep->base.sk)->hmac;
                int err;
 
-               desc->tfm = sctp_sk(ep->base.sk)->hmac;
-
-               err = crypto_shash_setkey(desc->tfm, ep->secret_key,
+               err = crypto_shash_setkey(tfm, ep->secret_key,
                                          sizeof(ep->secret_key)) ?:
-                     crypto_shash_digest(desc, (u8 *)bear_cookie, bodysize,
-                                         digest);
-               shash_desc_zero(desc);
-
+                     crypto_shash_tfm_digest(tfm, (u8 *)bear_cookie, bodysize,
+                                             digest);
                if (err) {
                        *error = -SCTP_IERROR_NOMEM;
                        goto fail;