[PATCH 3/6] net/tcp-ao: clear the aes_cmac_key when done

From: Thomas Huth

Date: Wed Aug 05 2026 - 10:37:35 EST


From: Thomas Huth <thuth@xxxxxxxxxx>

Clear the local aes_cmac_key structure via __cleanup() function
when we're done with it to avoid that sensitive data could leak on
the stack.

Signed-off-by: Thomas Huth <thuth@xxxxxxxxxx>
---
net/ipv4/tcp_ao.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv4/tcp_ao.c b/net/ipv4/tcp_ao.c
index a56bb79e15e0e..12c724fed8a26 100644
--- a/net/ipv4/tcp_ao.c
+++ b/net/ipv4/tcp_ao.c
@@ -141,7 +141,7 @@ void tcp_ao_calc_traffic_key(const struct tcp_ao_key *mkt, u8 *traffic_key,
traffic_key);
return;
case TCP_AO_ALGO_AES_128_CMAC: {
- struct aes_cmac_key k;
+ struct aes_cmac_key k __cleanup(aes_cmac_zeroize_key);

aes_cmac_preparekey(&k, mkt->key, AES_KEYSIZE_128);
aes_cmac(&k, input, input_len, traffic_key);
--
2.55.0