crypto: skcipher - fix crash in skcipher_walk_aead()
authorArd Biesheuvel <ard.biesheuvel@linaro.org>
Tue, 29 Nov 2016 13:05:31 +0000 (13:05 +0000)
committerHerbert Xu <herbert@gondor.apana.org.au>
Wed, 30 Nov 2016 12:01:43 +0000 (20:01 +0800)
commit3cbf61fb9fe24c0c3a1591b65175f8c5b3ddaac2
tree30d413f8d7c588130df5266e14dd8cf7bc23145b
parent7f329c17427ba517a9f6aa37133c73ff19bec5fb
crypto: skcipher - fix crash in skcipher_walk_aead()

The new skcipher_walk_aead() may crash in the following way due to
the walk flag SKCIPHER_WALK_PHYS not being cleared at the start of the
walk:

Unable to handle kernel NULL pointer dereference at virtual address 00000001
[..]
Internal error: Oops: 96000044 [#1] PREEMPT SMP
[..]
PC is at skcipher_walk_next+0x208/0x450
LR is at skcipher_walk_next+0x1e4/0x450
pc : [<ffff2b93b7104e20>] lr : [<ffff2b93b7104dfc>] pstate: 40000045
sp : ffffb925fa517940
[...]
[<ffff2b93b7104e20>] skcipher_walk_next+0x208/0x450
[<ffff2b93b710535c>] skcipher_walk_first+0x54/0x148
[<ffff2b93b7105664>] skcipher_walk_aead+0xd4/0x108
[<ffff2b93b6e77928>] ccm_encrypt+0x68/0x158

So clear the flag at the appropriate time.

Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
crypto/skcipher.c