kfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But
ctx_p->user.key is still used in the next line, which will lead to a
use after free.
We can call kfree_sensitive() after dev_dbg() to avoid the uaf.
Fixes:
|
||
|---|---|---|
| .. | ||
| cc_aead.c | ||
| cc_aead.h | ||
| cc_buffer_mgr.c | ||
| cc_buffer_mgr.h | ||
| cc_cipher.c | ||
| cc_cipher.h | ||
| cc_crypto_ctx.h | ||
| cc_debugfs.c | ||
| cc_debugfs.h | ||
| cc_driver.c | ||
| cc_driver.h | ||
| cc_fips.c | ||
| cc_fips.h | ||
| cc_hash.c | ||
| cc_hash.h | ||
| cc_host_regs.h | ||
| cc_hw_queue_defs.h | ||
| cc_kernel_regs.h | ||
| cc_lli_defs.h | ||
| cc_pm.c | ||
| cc_pm.h | ||
| cc_request_mgr.c | ||
| cc_request_mgr.h | ||
| cc_sram_mgr.c | ||
| cc_sram_mgr.h | ||
| Makefile | ||