lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 06 Apr 2020 08:45:18 -0700 From: Joe Perches <joe@...ches.com> To: Waiman Long <longman@...hat.com>, Andrew Morton <akpm@...ux-foundation.org>, David Howells <dhowells@...hat.com>, Jarkko Sakkinen <jarkko.sakkinen@...ux.intel.com>, James Morris <jmorris@...ei.org>, "Serge E. Hallyn" <serge@...lyn.com> Cc: linux-mm@...ck.org, keyrings@...r.kernel.org, linux-kernel@...r.kernel.org, Linus Torvalds <torvalds@...ux-foundation.org> Subject: Re: [PATCH] mm: Add kvfree_sensitive() for freeing sensitive data objects On Sun, 2020-04-05 at 22:37 -0400, Waiman Long wrote: > For kvmalloc'ed data object that contains sensitive information like > cryptographic key, we need to make sure that the buffer is always > cleared before freeing it. Using memset() alone for buffer clearing may > not provide certainty as the compiler may compile it away. To be sure, > the special memzero_explicit() has to be used. > > This patch introduces a new kvfree_sensitive() for freeing those > sensitive data objects allocated by kvmalloc(). The relevnat places > where kvfree_sensitive() can be used are modified to use it. Why isn't this called kvzfree like the existing kzfree?
Powered by blists - more mailing lists