summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorStephan Müller <smueller@chronox.de>2020-06-07 15:20:26 +0200
committerHerbert Xu <herbert@gondor.apana.org.au>2020-06-15 09:38:54 +0200
commit819966c06b759022e9932f328284314d9272b9f3 (patch)
tree90ddd360f92ed37ae23f52f4bb9fb6d0f16764d9
parentcrypto: marvell/octeontx - Fix a potential NULL dereference (diff)
downloadlinux-819966c06b759022e9932f328284314d9272b9f3.tar.xz
linux-819966c06b759022e9932f328284314d9272b9f3.zip
crypto: drbg - always try to free Jitter RNG instance
The Jitter RNG is unconditionally allocated as a seed source follwoing the patch 97f2650e5040. Thus, the instance must always be deallocated. Reported-by: syzbot+2e635807decef724a1fa@syzkaller.appspotmail.com Fixes: 97f2650e5040 ("crypto: drbg - always seeded with SP800-90B ...") Signed-off-by: Stephan Mueller <smueller@chronox.de> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
-rw-r--r--crypto/drbg.c6
1 files changed, 4 insertions, 2 deletions
diff --git a/crypto/drbg.c b/crypto/drbg.c
index 37526eb8c5d5..8d80d93cab97 100644
--- a/crypto/drbg.c
+++ b/crypto/drbg.c
@@ -1631,10 +1631,12 @@ static int drbg_uninstantiate(struct drbg_state *drbg)
if (drbg->random_ready.func) {
del_random_ready_callback(&drbg->random_ready);
cancel_work_sync(&drbg->seed_work);
- crypto_free_rng(drbg->jent);
- drbg->jent = NULL;
}
+ if (!IS_ERR_OR_NULL(drbg->jent))
+ crypto_free_rng(drbg->jent);
+ drbg->jent = NULL;
+
if (drbg->d_ops)
drbg->d_ops->crypto_fini(drbg);
drbg_dealloc_state(drbg);