[lvc-project] [PATCH 5.10] crypto: ecdh - explicitly zeroize private_key

Roman Demidov roman.demidov.nn at gmail.com
Fri Sep 11 15:31:37 MSK 2026


From: Joachim Vandersmissen <git at jvdsn.com>

commit 73e5984e540a76a2ee1868b91590c922da8c24c9 upstream.

private_key is overwritten with the key parameter passed in by the
caller (if present), or alternatively a newly generated private key.
However, it is possible that the caller provides a key (or the newly
generated key) which is shorter than the previous key. In that
scenario, some key material from the previous key would not be
overwritten. The easiest solution is to explicitly zeroize the entire
private_key array first.

Note that this patch slightly changes the behavior of this function:
previously, if the ecc_gen_privkey failed, the old private_key would
remain. Now, the private_key is always zeroized. This behavior is
consistent with the case where params.key is set and ecc_is_key_valid
fails.

Signed-off-by: Joachim Vandersmissen <git at jvdsn.com>
Signed-off-by: Herbert Xu <herbert at gondor.apana.org.au>
[ Roman: The zeroing is performed before ecdh_supported_curve() which is
not present in upstream but this does not change the fix's logic. ]
Signed-off-by: Roman Demidov <roman.demidov.nn at gmail.com>
---
Backport fix for BDU:2025-00987

 crypto/ecdh.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/crypto/ecdh.c b/crypto/ecdh.c
index 96f80c8f8e30..2e7acfc42155 100644
--- a/crypto/ecdh.c
+++ b/crypto/ecdh.c
@@ -43,6 +43,8 @@ static int ecdh_set_secret(struct crypto_kpp *tfm, const void *buf,
 	    params.key_size > sizeof(ctx->private_key))
 		return -EINVAL;
 
+	memset(ctx->private_key, 0, sizeof(ctx->private_key));
+
 	ndigits = ecdh_supported_curve(params.curve_id);
 	if (!ndigits)
 		return -EINVAL;
-- 
2.53.0




More information about the lvc-project mailing list