[PATCH 2/6] smb: clear the aes_cmac_key and aes_cmac_ctx when done
From: Thomas Huth
Date: Wed Aug 05 2026 - 10:37:25 EST
From: Thomas Huth <thuth@xxxxxxxxxx>
Clear the local crypto-related structures via __cleanup() functions
when we're done with them to avoid that sensitive data could leak on
the stack.
Note: cmac_ctx in ksmbd_sign_smb3_pdu() gets cleared in aes_cmac_final()
already, so this does not need a __cleanup() marker.
Signed-off-by: Thomas Huth <thuth@xxxxxxxxxx>
---
fs/smb/client/smb2transport.c | 4 ++--
fs/smb/server/auth.c | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/fs/smb/client/smb2transport.c b/fs/smb/client/smb2transport.c
index 1143ee52470a7..d23566da2ac81 100644
--- a/fs/smb/client/smb2transport.c
+++ b/fs/smb/client/smb2transport.c
@@ -464,8 +464,8 @@ smb3_calc_signature(struct smb_rqst *rqst, struct TCP_Server_Info *server)
unsigned char smb3_signature[SMB2_CMACAES_SIZE];
struct kvec *iov = rqst->rq_iov;
struct smb2_hdr *shdr = (struct smb2_hdr *)iov[0].iov_base;
- struct aes_cmac_key cmac_key;
- struct aes_cmac_ctx cmac_ctx;
+ struct aes_cmac_key cmac_key __cleanup(aes_cmac_zeroize_key);
+ struct aes_cmac_ctx cmac_ctx __cleanup(aes_cmac_zeroize_ctx);
struct smb_rqst drqst;
u8 key[SMB3_SIGN_KEY_SIZE];
diff --git a/fs/smb/server/auth.c b/fs/smb/server/auth.c
index 86f521e849d5e..f123e6cf9c424 100644
--- a/fs/smb/server/auth.c
+++ b/fs/smb/server/auth.c
@@ -505,7 +505,7 @@ void ksmbd_sign_smb2_pdu(struct ksmbd_conn *conn, char *key, struct kvec *iov,
void ksmbd_sign_smb3_pdu(struct ksmbd_conn *conn, char *key, struct kvec *iov,
int n_vec, char *sig)
{
- struct aes_cmac_key cmac_key;
+ struct aes_cmac_key cmac_key __cleanup(aes_cmac_zeroize_key);
struct aes_cmac_ctx cmac_ctx;
int i;
--
2.55.0