Re: [PATCH] crypto: sa2ul - Fix HMAC key preparation
From: Herbert Xu
Date: Fri Oct 02 2026 - 04:29:00 EST
On Tue, Sep 22, 2026 at 10:11:16PM -0700, Eric Biggers wrote:
> sa_prepare_iopads() has multiple bugs, as discussed at
> https://lore.kernel.org/linux-crypto/20260831055141.1632832-1-s-vadapalli@xxxxxx/T/#u
>
> - Commit 3bf533787910 ("crypto: sha256 - Use the partial block API")
> introduced a 1-byte buffer overflow in the SHA-256 case by making the
> crypto_shash_export() write 1 more than sizeof(struct sha256_state).
>
> - It never worked for HMAC keys longer than 64 bytes in the first place.
>
> Fix both of these bugs by just using the crypto library to prepare the
> key, like what the chelsio and qat drivers do. Also remove the
> pointless use of an indirect call.
>
> Fixes: 3bf533787910 ("crypto: sha256 - Use the partial block API")
> Fixes: d2c8ac187fc9 ("crypto: sa2ul - Add AEAD algorithm support")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
> ---
> drivers/crypto/sa2ul.c | 121 +++++++++--------------------------------
> 1 file changed, 27 insertions(+), 94 deletions(-)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt