Re: [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final()
From: Ard Biesheuvel
Date: Tue Oct 06 2026 - 06:13:02 EST
On Tue, 6 Oct 2026, at 10:34, Eric Biggers wrote:
> Use memzero_explicit() instead of a plain struct assignment to guarantee
> zeroization of the 'struct poly1305_desc_ctx'.
>
> Note that dead store elimination was only theoretically possible with
> link-time optimization here. But it's still worth fixing.
>
> Fixes: a1d93064094c ("crypto: poly1305 - expose init/update/final
> library interface")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Closes:
> https://sashiko.dev/#/bug/linux-c3a6bd76-f6ab-4203-892a-cd06f7aa0c34
> Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
> ---
> lib/crypto/poly1305.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
Reviewed-by: Ard Biesheuvel <ardb@xxxxxxxxxx>
> diff --git a/lib/crypto/poly1305.c b/lib/crypto/poly1305.c
> index f313ccc4b4dd2..048c7afe86138 100644
> --- a/lib/crypto/poly1305.c
> +++ b/lib/crypto/poly1305.c
> @@ -78,7 +78,7 @@ void poly1305_final(struct poly1305_desc_ctx *desc, u8 *dst)
> }
>
> poly1305_emit(&desc->state.h, dst, desc->s);
> - *desc = (struct poly1305_desc_ctx){};
> + memzero_explicit(desc, sizeof(*desc));
> }
> EXPORT_SYMBOL(poly1305_final);
>
>
> base-commit: 6a50ce0af5c91fd665d65d357af8ae55db1df7d0
> --
> 2.56.0