diff --git a/src/mesh/CryptoEngine.cpp b/src/mesh/CryptoEngine.cpp index f2c966cc7..bd199e8fd 100644 --- a/src/mesh/CryptoEngine.cpp +++ b/src/mesh/CryptoEngine.cpp @@ -403,11 +403,20 @@ void CryptoEngine::decrypt(uint32_t fromNode, uint64_t packetId, size_t numBytes // Generic implementation of AES-CTR encryption. void CryptoEngine::encryptAESCtr(CryptoKey _key, uint8_t *_nonce, size_t numBytes, uint8_t *bytes) { - std::unique_ptr ctr; - if (_key.length == 16) - ctr = std::unique_ptr(new CTR()); - else - ctr = std::unique_ptr(new CTR()); + // Reused instead of reallocated per packet: safe because all callers hold cryptLock and setKey/setIV reset the + // full cipher state. Lazy so overriding platforms reserve nothing; key material now lives until the next call. + static CTR *ctr128 = nullptr; + static CTR *ctr256 = nullptr; + CTRCommon *ctr; + if (_key.length == 16) { + if (!ctr128) + ctr128 = new CTR(); + ctr = ctr128; + } else { + if (!ctr256) + ctr256 = new CTR(); + ctr = ctr256; + } ctr->setKey(_key.bytes, _key.length); static uint8_t scratch[MAX_BLOCKSIZE]; memcpy(scratch, bytes, numBytes);