Skip to content

Commit

Permalink
[CRYPTO] api: fix writting into unallocated memory in setkey_aligned
Browse files Browse the repository at this point in the history
setkey_unaligned() commited in ca7c393
overwrites unallocated memory in the following memset() because
I used the wrong buffer length.

Signed-off-by: Sebastian Siewior <[email protected]>
Signed-off-by: Herbert Xu <[email protected]>
  • Loading branch information
sebastianas authored and herbertx committed Aug 6, 2007
1 parent d4ac247 commit 0681717
Show file tree
Hide file tree
Showing 4 changed files with 4 additions and 4 deletions.
2 changes: 1 addition & 1 deletion crypto/ablkcipher.c
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ static int setkey_unaligned(struct crypto_ablkcipher *tfm, const u8 *key, unsign
alignbuffer = (u8 *)ALIGN((unsigned long)buffer, alignmask + 1);
memcpy(alignbuffer, key, keylen);
ret = cipher->setkey(tfm, alignbuffer, keylen);
memset(alignbuffer, 0, absize);
memset(alignbuffer, 0, keylen);
kfree(buffer);
return ret;
}
Expand Down
2 changes: 1 addition & 1 deletion crypto/blkcipher.c
Original file line number Diff line number Diff line change
Expand Up @@ -352,7 +352,7 @@ static int setkey_unaligned(struct crypto_tfm *tfm, const u8 *key, unsigned int
alignbuffer = (u8 *)ALIGN((unsigned long)buffer, alignmask + 1);
memcpy(alignbuffer, key, keylen);
ret = cipher->setkey(tfm, alignbuffer, keylen);
memset(alignbuffer, 0, absize);
memset(alignbuffer, 0, keylen);
kfree(buffer);
return ret;
}
Expand Down
2 changes: 1 addition & 1 deletion crypto/cipher.c
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ static int setkey_unaligned(struct crypto_tfm *tfm, const u8 *key, unsigned int
alignbuffer = (u8 *)ALIGN((unsigned long)buffer, alignmask + 1);
memcpy(alignbuffer, key, keylen);
ret = cia->cia_setkey(tfm, alignbuffer, keylen);
memset(alignbuffer, 0, absize);
memset(alignbuffer, 0, keylen);
kfree(buffer);
return ret;

Expand Down
2 changes: 1 addition & 1 deletion crypto/hash.c
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ static int hash_setkey_unaligned(struct crypto_hash *crt, const u8 *key,
alignbuffer = (u8 *)ALIGN((unsigned long)buffer, alignmask + 1);
memcpy(alignbuffer, key, keylen);
ret = alg->setkey(crt, alignbuffer, keylen);
memset(alignbuffer, 0, absize);
memset(alignbuffer, 0, keylen);
kfree(buffer);
return ret;
}
Expand Down

0 comments on commit 0681717

Please sign in to comment.