Zeroise stack buffer containing private key

Signed-off-by: Neil Armstrong <narmstrong@baylibre.com>
diff --git a/library/pk_wrap.c b/library/pk_wrap.c
index 53cf7cb..59ec307 100644
--- a/library/pk_wrap.c
+++ b/library/pk_wrap.c
@@ -917,6 +917,7 @@
     ret = pk_ecdsa_sig_asn1_from_psa( sig, sig_len, sig_size );
 
 cleanup:
+    mbedtls_platform_zeroize( buf, sizeof( buf ) );
     status = psa_destroy_key( key_id );
     if( ret == 0 && status != PSA_SUCCESS )
         ret = mbedtls_pk_error_from_psa( status );