Re: [PATCH] crypto: caam - fix double-free in caam_rsa_set_priv_key_form()

From: Herbert Xu

Date: Fri Oct 02 2026 - 06:17:43 EST


On Wed, Sep 23, 2026 at 06:14:57PM +0800, ZhaoJinming wrote:
> caam_rsa_set_priv_key_form() frees the partially allocated key
> components (p, q, tmp1, tmp2, dp, dq) with kfree_sensitive() on its
> error path, but does not set those pointers to NULL afterward.
>
> When the function returns an error, caam_rsa_set_priv_key() jumps to
> its err label and calls caam_rsa_free_key(), which frees all of those
> same pointers again, resulting in a double-free.
>
> This is reachable when the allocation of q, tmp1, tmp2, dp, dq or qinv
> fails, e.g. under memory pressure, or for a malformed key whose CRT
> members decode to zero length and make caam_read_rsa_crt() return NULL.
>
> Set each pointer to NULL right after freeing it so that the subsequent
> caam_rsa_free_key() call becomes a no-op for the already-freed fields.
>
> Fixes: 52e26d77b8b3 ("crypto: caam - add support for RSA key form 2")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: ZhaoJinming <zhaojinming@xxxxxxxxxxxxx>
> ---
> drivers/crypto/caam/caampkc.c | 6 ++++++
> 1 file changed, 6 insertions(+)

Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt