| From e5046823f8fa3677341b541a25af2fcb99a5b1e0 Mon Sep 17 00:00:00 2001 |
| From: Eric Biggers <ebiggers@kernel.org> |
| Date: Wed, 25 Mar 2026 20:29:20 -0700 |
| Subject: lib/crypto: chacha: Zeroize permuted_state before it leaves scope |
| |
| From: Eric Biggers <ebiggers@kernel.org> |
| |
| commit e5046823f8fa3677341b541a25af2fcb99a5b1e0 upstream. |
| |
| Since the ChaCha permutation is invertible, the local variable |
| 'permuted_state' is sufficient to compute the original 'state', and thus |
| the key, even after the permutation has been done. |
| |
| While the kernel is quite inconsistent about zeroizing secrets on the |
| stack (and some prominent userspace crypto libraries don't bother at all |
| since it's not guaranteed to work anyway), the kernel does try to do it |
| as a best practice, especially in cases involving the RNG. |
| |
| Thus, explicitly zeroize 'permuted_state' before it goes out of scope. |
| |
| Fixes: c08d0e647305 ("crypto: chacha20 - Add a generic ChaCha20 stream cipher implementation") |
| Cc: stable@vger.kernel.org |
| Acked-by: Ard Biesheuvel <ardb@kernel.org> |
| Link: https://lore.kernel.org/r/20260326032920.39408-1-ebiggers@kernel.org |
| Signed-off-by: Eric Biggers <ebiggers@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| lib/crypto/chacha.c | 4 ++++ |
| 1 file changed, 4 insertions(+) |
| |
| --- a/lib/crypto/chacha.c |
| +++ b/lib/crypto/chacha.c |
| @@ -86,6 +86,8 @@ void chacha_block_generic(u32 *state, u8 |
| put_unaligned_le32(x[i] + state[i], &stream[i * sizeof(u32)]); |
| |
| state[12]++; |
| + |
| + memzero_explicit(x, sizeof(x)); |
| } |
| EXPORT_SYMBOL(chacha_block_generic); |
| |
| @@ -110,5 +112,7 @@ void hchacha_block_generic(const u32 *st |
| |
| memcpy(&stream[0], &x[0], 16); |
| memcpy(&stream[4], &x[12], 16); |
| + |
| + memzero_explicit(x, sizeof(x)); |
| } |
| EXPORT_SYMBOL(hchacha_block_generic); |