mirror of
https://github.com/torvalds/linux.git
synced 2026-09-27 11:02:03 +02:00
smb: client: Clear sensitive stack and heap data in smb2ops.c
Make sure to not leak key-related data via the heap or the stack by using kfree_sensitive() or memzero_explicit() here. Signed-off-by: Thomas Huth <thuth@redhat.com> Signed-off-by: Namjae Jeon <linkinjeon@kernel.org> Signed-off-by: Paulo Alcantara <pc@manguebit.org>
This commit is contained in:
parent
3d93986f68
commit
55a1ad8413
|
|
@ -1569,7 +1569,7 @@ SMB2_request_res_key(const unsigned int xid, struct cifs_tcon *tcon,
|
|||
memcpy(pcchunk->SourceKey, res_key->ResumeKey, COPY_CHUNK_RES_KEY_SIZE);
|
||||
|
||||
req_res_key_exit:
|
||||
kfree(res_key);
|
||||
kfree_sensitive(res_key);
|
||||
return rc;
|
||||
}
|
||||
|
||||
|
|
@ -4633,7 +4633,7 @@ crypt_message(struct TCP_Server_Info *server, int num_rqst,
|
|||
rc = crypto_aead_setkey(tfm, key, SMB3_GCM256_CRYPTKEY_SIZE);
|
||||
else
|
||||
rc = crypto_aead_setkey(tfm, key, SMB3_GCM128_CRYPTKEY_SIZE);
|
||||
|
||||
memzero_explicit(key, sizeof(key));
|
||||
if (rc) {
|
||||
cifs_server_dbg(VFS, "%s: Failed to set aead key %d\n", __func__, rc);
|
||||
return rc;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user