[PATCH 1/2] keys/trusted_keys: return immediately after TPM unseal failure
From: Srish Srinivasan
Date: Wed Sep 02 2026 - 06:47:39 EST
trusted_tpm_unseal() proceeds to pcrlock() when the TPM unseal operation
fails. If pcrlock() succeeds, its return value overwrites the unseal error,
causing key instantiation to succeed.
Return immediately when unseal fails to preserve the original error.
Fixes: 5d0682be3189 ("KEYS: trusted: Add generic trusted keys framework")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Srish Srinivasan <ssrish@xxxxxxxxxxxxx>
---
security/keys/trusted-keys/trusted_tpm1.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/security/keys/trusted-keys/trusted_tpm1.c b/security/keys/trusted-keys/trusted_tpm1.c
index bf0bf7f36970..1168ca235205 100644
--- a/security/keys/trusted-keys/trusted_tpm1.c
+++ b/security/keys/trusted-keys/trusted_tpm1.c
@@ -923,8 +923,10 @@ static int trusted_tpm_unseal(struct trusted_key_payload *p, char *datablob)
ret = tpm2_unseal_trusted(chip, p, options);
else
ret = key_unseal(p, options);
- if (ret < 0)
+ if (ret < 0) {
pr_info("key_unseal failed (%d)\n", ret);
+ return ret;
+ }
if (options->pcrlock) {
ret = pcrlock(options->pcrlock);
--
2.53.0