s390/pkey: Wipe sensitive data on failure
authorHolger Dengler <dengler@linux.ibm.com>
Tue, 7 May 2024 15:03:18 +0000 (17:03 +0200)
committerAlexander Gordeev <agordeev@linux.ibm.com>
Tue, 14 May 2024 18:16:33 +0000 (20:16 +0200)
Wipe sensitive data from stack also if the copy_to_user() fails.

Suggested-by: Heiko Carstens <hca@linux.ibm.com>
Reviewed-by: Harald Freudenberger <freude@linux.ibm.com>
Reviewed-by: Ingo Franzki <ifranzki@linux.ibm.com>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Holger Dengler <dengler@linux.ibm.com>
Signed-off-by: Alexander Gordeev <agordeev@linux.ibm.com>
drivers/s390/crypto/pkey_api.c

index 933894065623ed45736b2a1d94d9f43754ff762b..179287157c2fe1e8a2f03eb10ba8e09077f29c5c 100644 (file)
@@ -1377,7 +1377,7 @@ static long pkey_unlocked_ioctl(struct file *filp, unsigned int cmd,
                if (rc)
                        break;
                if (copy_to_user(ucs, &kcs, sizeof(kcs)))
-                       return -EFAULT;
+                       rc = -EFAULT;
                memzero_explicit(&kcs, sizeof(kcs));
                break;
        }
@@ -1412,7 +1412,7 @@ static long pkey_unlocked_ioctl(struct file *filp, unsigned int cmd,
                if (rc)
                        break;
                if (copy_to_user(ucp, &kcp, sizeof(kcp)))
-                       return -EFAULT;
+                       rc = -EFAULT;
                memzero_explicit(&kcp, sizeof(kcp));
                break;
        }