]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
crypto: inside-secure - fix zeroing of the request in ahash_exit_inv
authorAntoine Tenart <antoine.tenart@bootlin.com>
Mon, 27 May 2019 14:51:01 +0000 (16:51 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 27 Jan 2020 13:50:53 +0000 (14:50 +0100)
[ Upstream commit b926213d6fede9c9427d7c12eaf7d9f0895deb4e ]

A request is zeroed in safexcel_ahash_exit_inv(). This request total
size is EIP197_AHASH_REQ_SIZE while the memset zeroing it uses
sizeof(struct ahash_request), which happens to be less than
EIP197_AHASH_REQ_SIZE. This patch fixes it.

Fixes: f6beaea30487 ("crypto: inside-secure - authenc(hmac(sha256), cbc(aes)) support")
Signed-off-by: Antoine Tenart <antoine.tenart@bootlin.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/crypto/inside-secure/safexcel_hash.c

index ac9282c1a5ec13048037a8c84db819c27fc88fdf..9a02f64a45b96f8946b5f6005318d933fa4a0501 100644 (file)
@@ -486,7 +486,7 @@ static int safexcel_ahash_exit_inv(struct crypto_tfm *tfm)
        struct safexcel_inv_result result = {};
        int ring = ctx->base.ring;
 
-       memset(req, 0, sizeof(struct ahash_request));
+       memset(req, 0, EIP197_AHASH_REQ_SIZE);
 
        /* create invalidation request */
        init_completion(&result.completion);