]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
KEYS: trusted_tpm1: Compare HMAC values in constant time
authorEric Biggers <ebiggers@kernel.org>
Sat, 9 Aug 2025 17:19:39 +0000 (10:19 -0700)
committerJarkko Sakkinen <jarkko@kernel.org>
Sat, 27 Sep 2025 18:05:06 +0000 (21:05 +0300)
commiteed0e3d305530066b4fc5370107cff8ef1a0d229
treea0c27772822b9234c1d01b986134d9d8ae595376
parentfec734e8d564d55fb6bd4909ae2e68814d21d0a1
KEYS: trusted_tpm1: Compare HMAC values in constant time

To prevent timing attacks, HMAC value comparison needs to be constant
time.  Replace the memcmp() with the correct function, crypto_memneq().

[For the Fixes commit I used the commit that introduced the memcmp().
It predates the introduction of crypto_memneq(), but it was still a bug
at the time even though a helper function didn't exist yet.]

Fixes: d00a1c72f7f4 ("keys: add new trusted key-type")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
security/keys/trusted-keys/trusted_tpm1.c