crypto: ccree - fix AEAD decrypt auth fail
On AEAD decryption authentication failure we are suppose to
zero out the output plaintext buffer. However, we've missed
skipping the optional associated data that may prefix the
ciphertext. This commit fixes this issue.
Signed-off-by: Gilad Ben-Yossef <gilad@benyossef.com>
Fixes: e88b27c8ea
("crypto: ccree - use std api sg_zero_buffer")
Cc: stable@vger.kernel.org
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This commit is contained in:
Родитель
684cf266eb
Коммит
2a6bc713f1
|
@ -237,7 +237,7 @@ static void cc_aead_complete(struct device *dev, void *cc_req, int err)
|
||||||
* revealed the decrypted message --> zero its memory.
|
* revealed the decrypted message --> zero its memory.
|
||||||
*/
|
*/
|
||||||
sg_zero_buffer(areq->dst, sg_nents(areq->dst),
|
sg_zero_buffer(areq->dst, sg_nents(areq->dst),
|
||||||
areq->cryptlen, 0);
|
areq->cryptlen, areq->assoclen);
|
||||||
err = -EBADMSG;
|
err = -EBADMSG;
|
||||||
}
|
}
|
||||||
/*ENCRYPT*/
|
/*ENCRYPT*/
|
||||||
|
|
Загрузка…
Ссылка в новой задаче