Re: [PATCH] lib/crypto: poly1305: Use memzero_explicit() in poly1305_final()

From: Eric Biggers

Date: Tue Oct 06 2026 - 08:26:25 EST


On Tue, Oct 06, 2026 at 10:34:32AM +0200, Eric Biggers wrote:
> Use memzero_explicit() instead of a plain struct assignment to guarantee
> zeroization of the 'struct poly1305_desc_ctx'.
>
> Note that dead store elimination was only theoretically possible with
> link-time optimization here. But it's still worth fixing.
>
> Fixes: a1d93064094c ("crypto: poly1305 - expose init/update/final library interface")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Closes: https://sashiko.dev/#/bug/linux-c3a6bd76-f6ab-4203-892a-cd06f7aa0c34
> Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
> ---
> lib/crypto/poly1305.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)

Applied to https://git.kernel.org/pub/scm/linux/kernel/git/ebiggers/linux.git/log/?h=libcrypto-next

- Eric