diff --git a/env/Kconfig b/env/Kconfig
index f12ef286345855eb604109df7cc70b4d95c48673..024d4d79bd49117694f0093362cdf5d45cfc4321 100644
--- a/env/Kconfig
+++ b/env/Kconfig
@@ -375,6 +375,14 @@ config ENV_IS_IN_UBI
 
 endchoice
 
+config ENV_AES
+	bool "AES-128 encryption for stored environment (DEPRECATED)"
+	help
+	  Enable this to have the on-device stored environment be encrypted
+	  with AES-128.  The implementation here however has security
+	  complications and is not recommended for use.  Please see
+	  CVE-2017-3225 and CVE-2017-3226 for more details.
+
 config ENV_FAT_INTERFACE
 	string "Name of the block device for the environment"
 	depends on ENV_IS_IN_FAT
diff --git a/scripts/config_whitelist.txt b/scripts/config_whitelist.txt
index a9fb068e925b88733b29d249b8c6352e9f229077..9ce0c3f039ffa26e16b6e31897813ac42f13b590 100644
--- a/scripts/config_whitelist.txt
+++ b/scripts/config_whitelist.txt
@@ -574,7 +574,6 @@ CONFIG_ENV_ACCESS_IGNORE_FORCE
 CONFIG_ENV_ADDR
 CONFIG_ENV_ADDR_FLEX
 CONFIG_ENV_ADDR_REDUND
-CONFIG_ENV_AES
 CONFIG_ENV_BASE
 CONFIG_ENV_CALLBACK_LIST_DEFAULT
 CONFIG_ENV_CALLBACK_LIST_STATIC