linux/lib/crypto
Eric Biggers 74d74bb78a lib/crypto: aes: Fix missing MMU protection for AES S-box
__cacheline_aligned puts the data in the ".data..cacheline_aligned"
section, which isn't marked read-only i.e. it doesn't receive MMU
protection.  Replace it with ____cacheline_aligned which does the right
thing and just aligns the data while keeping it in ".rodata".

Fixes: b5e0b032b6 ("crypto: aes - add generic time invariant AES cipher")
Cc: stable@vger.kernel.org
Reported-by: Qingfang Deng <dqfext@gmail.com>
Closes: https://lore.kernel.org/r/20260105074712.498-1-dqfext@gmail.com/
Acked-by: Ard Biesheuvel <ardb@kernel.org>
Link: https://lore.kernel.org/r/20260107052023.174620-1-ebiggers@kernel.org
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
2026-01-08 11:14:59 -08:00
..
arm
arm64
mips
mpi
powerpc
riscv lib/crypto: riscv: Add poly1305-core.S to .gitignore 2025-12-14 10:18:22 -08:00
s390
sparc
tests lib/crypto: tests: polyval_kunit: Increase iterations for preparekey in IRQs 2026-01-08 11:14:59 -08:00
x86
Kconfig lib/crypto: riscv: Depend on RISCV_EFFICIENT_VECTOR_UNALIGNED_ACCESS 2025-12-09 15:10:21 -08:00
Makefile lib/crypto: blake2b: Roll up BLAKE2b round loop on 32-bit 2025-12-09 15:10:21 -08:00
aes.c lib/crypto: aes: Fix missing MMU protection for AES S-box 2026-01-08 11:14:59 -08:00
aescfb.c
aesgcm.c
arc4.c
blake2b.c lib/crypto: blake2b: Roll up BLAKE2b round loop on 32-bit 2025-12-09 15:10:21 -08:00
blake2s.c lib/crypto: blake2s: Replace manual unrolling with unrolled_full 2025-12-09 15:10:21 -08:00
chacha-block-generic.c
chacha.c
chacha20poly1305-selftest.c
chacha20poly1305.c
curve25519-fiat32.c
curve25519-hacl64.c
curve25519.c
des.c
fips.h
gf128mul.c
hash_info.c
md5.c
memneq.c
poly1305-donna32.c
poly1305-donna64.c
poly1305.c
polyval.c
sha1.c
sha3.c
sha256.c
sha512.c
simd.c
sm3.c
utils.c