Re: [PATCH] crypto: chacha20poly1305 - Fix missing state zeroization in xchacha decrypt

From: Eric Biggers

Date: Sun Oct 04 2026 - 12:52:53 EST


On Sun, Oct 04, 2026 at 08:50:47AM +0530, Mohamad Raizudeen wrote:
> No, none that exist today. The only in-tree callers are the wireguard
> cookie code and the kunit test and I agree the cookie has no forward
> secrecy concerns. My only thought is that the function is
> EXPORT_SYMBOL()ed, so a future caller with a long term key would leave
> the derived subkey on the stack and since chacha20poly1305_decrypt()
> already wipes the state, having the xchacha variant do the same seemed
> like safer default.
>
> Also, Eric requested a v2 that moves the zeroization into the helper
> function for consistency with the encrypt path, so I will be sending
> that out shortly.
>
> Thanks,
> Mohamad Raizudeen

I agree: the crypto code should be compatible with callers that need the
key to be zeroized, even if none needs it right now. Otherwise it's
just way too subtle, with some functions doing it and others not.

- Eric