| From ce0ae266feaf35930394bd770c69778e4ef03ba9 Mon Sep 17 00:00:00 2001 |
| From: Tom Lendacky <thomas.lendacky@amd.com> |
| Date: Thu, 25 Feb 2016 16:48:13 -0600 |
| Subject: crypto: ccp - memset request context to zero during import |
| |
| From: Tom Lendacky <thomas.lendacky@amd.com> |
| |
| commit ce0ae266feaf35930394bd770c69778e4ef03ba9 upstream. |
| |
| Since a crypto_ahash_import() can be called against a request context |
| that has not had a crypto_ahash_init() performed, the request context |
| needs to be cleared to insure there is no random data present. If not, |
| the random data can result in a kernel oops during crypto_ahash_update(). |
| |
| Signed-off-by: Tom Lendacky <thomas.lendacky@amd.com> |
| Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| drivers/crypto/ccp/ccp-crypto-aes-cmac.c | 1 + |
| drivers/crypto/ccp/ccp-crypto-sha.c | 1 + |
| 2 files changed, 2 insertions(+) |
| |
| --- a/drivers/crypto/ccp/ccp-crypto-aes-cmac.c |
| +++ b/drivers/crypto/ccp/ccp-crypto-aes-cmac.c |
| @@ -244,6 +244,7 @@ static int ccp_aes_cmac_import(struct ah |
| /* 'in' may not be aligned so memcpy to local variable */ |
| memcpy(&state, in, sizeof(state)); |
| |
| + memset(rctx, 0, sizeof(*rctx)); |
| rctx->null_msg = state.null_msg; |
| memcpy(rctx->iv, state.iv, sizeof(rctx->iv)); |
| rctx->buf_count = state.buf_count; |
| --- a/drivers/crypto/ccp/ccp-crypto-sha.c |
| +++ b/drivers/crypto/ccp/ccp-crypto-sha.c |
| @@ -233,6 +233,7 @@ static int ccp_sha_import(struct ahash_r |
| /* 'in' may not be aligned so memcpy to local variable */ |
| memcpy(&state, in, sizeof(state)); |
| |
| + memset(rctx, 0, sizeof(*rctx)); |
| rctx->type = state.type; |
| rctx->msg_bits = state.msg_bits; |
| rctx->first = state.first; |