1
0
mirror of https://github.com/Mbed-TLS/mbedtls.git synced 2025-12-14 02:22:15 +03:00

Merge pull request #1317 from gilles-peskine-arm/zeroize-psa-202503-2.28

Backport 2.28: Zeroize PSA temporary heap buffers
This commit is contained in:
Gilles Peskine
2025-03-11 17:38:36 +01:00
committed by GitHub
2 changed files with 17 additions and 6 deletions

View File

@@ -0,0 +1,2 @@
Security
* Zeroize temporary heap buffers used in PSA operations.

View File

@@ -6171,16 +6171,22 @@ psa_status_t psa_crypto_local_input_alloc(const uint8_t *input, size_t input_len
return PSA_SUCCESS;
error:
mbedtls_free(local_input->buffer);
local_input->buffer = NULL;
if (local_input->buffer != NULL) {
mbedtls_platform_zeroize(local_input->buffer, local_input->length);
mbedtls_free(local_input->buffer);
local_input->buffer = NULL;
}
local_input->length = 0;
return status;
}
void psa_crypto_local_input_free(psa_crypto_local_input_t *local_input)
{
mbedtls_free(local_input->buffer);
local_input->buffer = NULL;
if (local_input->buffer != NULL) {
mbedtls_platform_zeroize(local_input->buffer, local_input->length);
mbedtls_free(local_input->buffer);
local_input->buffer = NULL;
}
local_input->length = 0;
}
@@ -6223,8 +6229,11 @@ psa_status_t psa_crypto_local_output_free(psa_crypto_local_output_t *local_outpu
return status;
}
mbedtls_free(local_output->buffer);
local_output->buffer = NULL;
if (local_output->buffer != NULL) {
mbedtls_platform_zeroize(local_output->buffer, local_output->length);
mbedtls_free(local_output->buffer);
local_output->buffer = NULL;
}
local_output->length = 0;
return PSA_SUCCESS;