Re: [PATCH v3] lib/crypto: chacha20poly1305: zeroize state in __chacha20poly1305_decrypt
From: Eric Biggers
Date: Mon Oct 05 2026 - 11:25:32 EST
On Mon, Oct 05, 2026 at 08:33:24PM +0530, Mohamad Raizudeen wrote:
> The `__chacha20poly1305_decrypt` function does not zeroize the chacha
> state, unlike its encrypt counterpart. The regular
> `chacha20poly1305_decrypt` function handles this by manually calling
> chacha_zeroize_state(). However, `xchacha20poly1305_decrypt` returns
> the result directly without clearing the state, leaving the derived
> chacha20 subkey on the stack.
>
> Because this function is EXPORT_SYMBOL()ed, this is an ABI robustness
> improvement. To ensure consistent and safe cleanup for any future
> callers, move the chacha_zeroize_state() call into
> `__chacha20poly1305_decrypt()` itself, so the helper cleans up after its
> own state just like `__chacha20poly1305_encrypt()` does.
>
> Additionally, moved the src_len check to the callers so the state is not
> initialized on invalid inputs, matching the logic in
> chacha20poly1305_crypt_sg_inplace().
>
> Suggested-by: Ard Biesheuvel <ardb@xxxxxxxxxx>
> Signed-off-by: Mohamad Raizudeen <raizudeen.kerneldev@xxxxxxxxx>
> ---
> Changes in v3:
> - Remove Fixes and Cc: stable tags, as this is an ABI robustness
> improvement rather than a fix.
> - Move the src_len check to the callers so the state is not initialized
> on invalid inputs.
> - Fix whitespace and ordering of the chacha_zeroize_state() to match
> chacha20poly1305_crypt_sg_inplace().
Applied to https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git/log/?h=libcrypto-next
- Eric