summaryrefslogtreecommitdiff
path: root/drivers/s390/crypto
diff options
context:
space:
mode:
authorPaolo Bonzini <pbonzini@redhat.com>2026-09-21 06:09:47 -0400
committerPaolo Bonzini <pbonzini@redhat.com>2026-09-21 06:09:47 -0400
commitec2ee09cb943a075c9b947a59ff7db0e3af66e75 (patch)
tree200d65c2e8075e569986fcb775f1a077511a18e5 /drivers/s390/crypto
parentd599822bdb66aeec5ec76297b0fc6efaaeefe07c (diff)
parent6b1bca1b1ab77f60a62087337bfe6e2f0efb9e6d (diff)
Merge tag 'kvmarm-fixes-7.3-1' of https://git.kernel.org/pub/scm/linux/kernel/git/kvmarm/kvmarm into HEAD
KVM/arm64 changes for 7.3, take #2 - Invalidate the ITS translation cache when the guest changes the base address of the ITS tables (Fuad Tabba) - Skip saving ITS devices with device IDs that are out-of-bounds rather than failing the entire ITS save ioctl (Fuad Tabba) - Close race between VM teardown and invalidations of nested MMUs when handling MMU operations that are allowed to block (Lorenzo Stoakes) - Various fixes for the handling of the host's untrusted SVE configuration in pKVM (Fuad Tabba) - Make sure that empty SMCCC ranges based at 0 are rejected by the kvm_smccc_set_filter() (Karl Mehltretter) - Revoke the host mapping for pKVM's private stack pages, along with a new sanity check that all mappings in the hyp's private VA range have been correctly marked as hyp-owned (Fuad Tabba) - Lifetime fixes for the array of shadow stage-2 MMUs, ensuring that concurrent vCPU initialization cannot relocate in-use MMUs. Defer the freeing of shadow stage-2 MMUs to the point that no other users (e.g. MMU notifier) could reference them (Marc Zyngier) - Drop useless WARN when rejecting an unsupported ioctl for pKVM (Fuad Tabba) - Fix the steal_time selftest to install correctly-sized mappings for non-4K hosts (Sebastian Ott) - Correct mapping of fine-grained trap for GCSPOPX instruction (Mark Brown) - Fix KVM_BUG_ON() due to missing handling of DBGBXVR<n> from 32-bit guests (Karl Mehltretter)
Diffstat (limited to 'drivers/s390/crypto')
-rw-r--r--drivers/s390/crypto/zcrypt_cca_key.h1
-rw-r--r--drivers/s390/crypto/zcrypt_ccamisc.c15
2 files changed, 15 insertions, 1 deletions
diff --git a/drivers/s390/crypto/zcrypt_cca_key.h b/drivers/s390/crypto/zcrypt_cca_key.h
index f5907b67db29..8a69eed75040 100644
--- a/drivers/s390/crypto/zcrypt_cca_key.h
+++ b/drivers/s390/crypto/zcrypt_cca_key.h
@@ -219,6 +219,7 @@ static inline int zcrypt_type6_crt_key(struct ica_rsa_modexpo_crt *crt, void *p)
copy_from_user(key->key_parts + 2 * long_len + 2 * short_len,
crt->u_mult_inv, long_len))
return -EFAULT;
+ memset(key->key_parts + 3 * long_len + 2 * short_len, 0, pad_len);
memset(key->key_parts + 3 * long_len + 2 * short_len + pad_len,
0xff, crt->inputdatalength);
pub = (struct cca_public_sec *)(key->key_parts + key_len);
diff --git a/drivers/s390/crypto/zcrypt_ccamisc.c b/drivers/s390/crypto/zcrypt_ccamisc.c
index d4ce6352b5b2..19909bf43dc9 100644
--- a/drivers/s390/crypto/zcrypt_ccamisc.c
+++ b/drivers/s390/crypto/zcrypt_ccamisc.c
@@ -1158,8 +1158,21 @@ static int _ip_cprb_helper(u16 cardnr, u16 domain,
/* do not check the key here, it may be incomplete */
- /* copy the vlsc key token back */
+ /*
+ * Copy the vlsc key token back.
+ * The available space in the destination (key_token) and the source
+ * (t) buffer is always larger as the valid range of prepparm->kb.len.
+ * Validate t->len by comparing it with the length information in the
+ * param block of the request (prepparm->kb.len)
+ * The value range of prepparm->kb.len has been checked above.
+ */
t = (struct cipherkeytoken *)prepparm->kb.tlv1.key_token;
+ if (t->len != prepparm->kb.len - 3 * sizeof(uint16_t)) {
+ ZCRYPT_DBF_ERR("%s reply with invalid key_token length %u\n",
+ __func__, t->len);
+ rc = -EIO;
+ goto out;
+ }
memcpy(key_token, t, t->len);
*key_token_size = t->len;