Re: [PATCH] arm64: scrub vector and pointer auth state on task death

From: Will Deacon

Date: Wed Sep 30 2026 - 04:08:33 EST


On Wed, Sep 30, 2026 at 06:36:47AM +0000, Bradley Morgan wrote:
> When a task dies its SVE, SME and FPSIMD register state, and its
> pointer auth keys, stay in freed slab pages until the allocator hands
> them out again. init_on_free=1 users get this wiped for the whole heap
> but the option is expensive, so it is off in most builds.
>
> The vector registers are not idle memory: userspace crypto runs
> AES-GCM and Argon2 through SVE, so key material ends up in
> sve_state, sme_state and thread_struct. On task exit and on the
> exec and vector length reallocation paths those buffers are
> dropped with a plain kfree(), and on task death the register file
> copy embedded in thread_struct is not wiped at all. Anything that
> reads the freed slab back (slab bugs, cold boot, a leaked page)
> gets the dead task's keys.
>
> Scrub it. kfree_sensitive() already exists for this exact job,
> so the freeing sites just switch to it. The register file copy
> and the pointer auth keys embedded in thread_struct cannot go
> through kfree_sensitive(), so arch_release_task_struct() zeroes
> them directly with memzero_explicit().

I don't really find this very compelling, tbh. Presumably this data can
end up all over the place: on the stack, in a vCPU structure, in a GPR
so it really just feels like doing something for the sake of feeling like
we're making the kernel more secure rather than actually adding any
tangible benefits. There are also lots of things you're not covering,
so it's not clear why this is either necessary or sufficient.

What prompted you to do this?

Will

P.S. This ended up in my spam for some reason.