Re: [PATCH v5 00/10] crypto: Provide a function for zeroizing crypto_aes_ctx

From: Herbert Xu

Date: Fri Sep 04 2026 - 06:06:15 EST


On Mon, Aug 10, 2026 at 11:29:55AM +0200, Thomas Huth wrote:
> Several crypto drivers need to zeroize their local crypto_aes_ctx
> structures after use to avoid leaking key material on the stack.
> Currently some call sites do this with their own memzero_explicit()
> call, which is error-prone since it is easy to miss a return path
> (what already happened in a driver). Some other call sites miss
> to clear crypto_aes_ctx completely.
>
> To improve this situation, the first patch introduces an aes_zeroize_ctx()
> helper that can be used with __cleanup() to automatically zeroize the
> context when it goes out of scope. The following 6 patches add this
> __cleanup() to spots in the code where this has been forgotten so far.
> The final patches change some files to do the zeroization with
> the new __cleanup() way instead of calling memzero_explicit() manually.
>
> v5:
> - Use aes_check_keylen() in the eip93 patch and in the 1st safexcel patch
>
> v4:
> - Updated the function description in the first patch
> - Fixed "return err" bug in the "safexcel - Rework cleanup..." patch
>
> v3:
> - Renamed aes_clear_ctx() to aes_zeroize_ctx()
> - Split up the safeexcel patch to rework safexcel_aead_setkey in a
> separate patch
> - Removed goto in the padlock patch
>
> v2:
> - Rebased onto cryptodev master branch, updated the "qat" patch accordingly
>
> Thomas Huth (10):
> crypto: Provide a wrapper function for zeroizing crypto_aes_ctx
> crypto: aspeed - clear the crypto_aes_ctx when done
> crypto: padlock-aes - clear the crypto_aes_ctx when done
> crypto: sa2ul - clear the crypto_aes_ctx when done
> crypto: arm/aes-neonbs - clear the crypto_aes_ctx when done
> crypto: arm64/aes-neonbs - clear the crypto_aes_ctx when done
> crypto: qat - zeroize crypto_aes_ctx with __cleanup(aes_zeroize_ctx)
> crypto: safexcel - Simplify the check for a valid AES key
> crypto: safexcel - zeroize crypto_aes_ctx with
> __cleanup(aes_zeroize_ctx)
> crypto: eip93 - Simplify the check for a valid AES key
>
> arch/arm/crypto/aes-neonbs-glue.c | 2 +-
> arch/arm64/crypto/aes-neonbs-glue.c | 2 +-
> drivers/crypto/aspeed/aspeed-hace-crypto.c | 3 +--
> .../crypto/inside-secure/eip93/eip93-aead.c | 3 +--
> .../crypto/inside-secure/safexcel_cipher.c | 16 +++++---------
> drivers/crypto/inside-secure/safexcel_hash.c | 3 +--
> .../crypto/intel/qat/qat_common/qat_algs.c | 3 +--
> drivers/crypto/padlock-aes.c | 22 +++++++++----------
> drivers/crypto/sa2ul.c | 2 +-
> include/crypto/aes.h | 13 +++++++++++
> 10 files changed, 35 insertions(+), 34 deletions(-)
>
> --
> 2.55.0

All applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt