[PATCH v2] crypto: rsassa-pkcs1: align DMA buffer to ARCH_DMA_MINALIGN
From: Changwei Zou
Date: Mon Jul 27 2026 - 18:43:29 EST
out_buf is used as a DMA buffer for the RSA verification operation.
If out_buf is not aligned to ARCH_DMA_MINALIGN, cacheline sharing
problems (data corruption) would occur on CPUs with DMA-incoherent caches,
leading to -EKEYREJECTED.
Fix by aligning out_buf to ARCH_DMA_MINALIGN using PTR_ALIGN(), and
allocating ARCH_DMA_MINALIGN extra bytes in the child_req allocation
to accommodate the alignment padding.
The intermittent error 'Key was rejected by service' on i.MX8 with CAAM
can be triggered when loading signed kernel modules.
for i in $(seq 1 100); do
sudo modprobe xfs 2>&1 && echo "SUCCESS on attempt $i" \
&& sudo rmmod xfs || echo "FAILED on attempt $i"
done
Fixes: 8552cb04e083 ("crypto: rsassa-pkcs1 - Copy source data for SG list")
Signed-off-by: Changwei Zou <changwei.zou@xxxxxxxxxxxxx>
---
crypto/rsassa-pkcs1.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/crypto/rsassa-pkcs1.c b/crypto/rsassa-pkcs1.c
index 94fa5e9600e7..a8d90959c871 100644
--- a/crypto/rsassa-pkcs1.c
+++ b/crypto/rsassa-pkcs1.c
@@ -7,6 +7,8 @@
* Copyright (c) 2015 - 2024 Intel Corporation
*/
+#include <linux/align.h>
+#include <linux/cache.h>
#include <linux/module.h>
#include <linux/scatterlist.h>
#include <crypto/akcipher.h>
@@ -237,12 +239,13 @@ static int rsassa_pkcs1_verify(struct crypto_sig *tfm,
return -EINVAL;
/* RFC 8017 sec 8.2.2 step 2 - RSA verification */
- child_req = kmalloc(sizeof(*child_req) + child_reqsize + ctx->key_size,
- GFP_KERNEL);
+ child_req = kmalloc(sizeof(*child_req) + child_reqsize +
+ ctx->key_size + ARCH_DMA_MINALIGN, GFP_KERNEL);
if (!child_req)
return -ENOMEM;
- out_buf = (u8 *)(child_req + 1) + child_reqsize;
+ out_buf = PTR_ALIGN((u8 *)(child_req + 1) + child_reqsize,
+ ARCH_DMA_MINALIGN);
memcpy(out_buf, src, slen);
crypto_init_wait(&cwait);
--
2.43.0