crypto: drbg - Fix the fips_enabled priority boost

commit a8a1f93080 upstream.

When fips_enabled=1, it seems to have been intended for one of the
algorithms defined in crypto/drbg.c to be the highest priority "stdrng"
algorithm, so that it is what is used by "stdrng" users.

However, the code only boosts the priority to 400, which is less than
the priority 500 used in drivers/crypto/caam/caamprng.c.  Thus, the CAAM
RNG could be used instead.

Fix this by boosting the priority by 2000 instead of 200.

Fixes: 541af946fe ("crypto: drbg - SP800-90A Deterministic Random Bit Generator")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Eric Biggers
2026-07-24 16:02:52 +02:00
committed by Greg Kroah-Hartman
parent d955e2127c
commit e3155eb0ea
+1 -1
View File
@@ -2095,7 +2095,7 @@ static inline void __init drbg_fill_array(struct rng_alg *alg,
* it is selected.
*/
if (fips_enabled)
alg->base.cra_priority += 200;
alg->base.cra_priority += 2000;
alg->base.cra_ctxsize = sizeof(struct drbg_state);
alg->base.cra_module = THIS_MODULE;