Re: [PATCH 2/4] selinux: require a class's permission values to cover its permission count

Paul Moore <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,org.kernel.vger.selinux
Message-ID <[email protected]>
On Jul 31, 2026 Bryam Vargas <[email protected]> wrote:
> 
> security_get_permissions() sizes an array by the class's permissions.nprim
> and fills it at value - 1, from the inherited common's permission table and
> then the class's own. A value no permission defines leaves a NULL that
> sel_make_perm_files() passes to d_alloc_name(), an oops inside
> sel_write_load() that strands selinux_state.policy_mutex and leaves every
> later load in uninterruptible sleep; two permissions sharing a value
> overwrite the first kstrdup(). Bounding each value by nprim catches
> neither, and neither would a count: the symbol table is keyed on the
> permission name, so duplicates pass.
> 
> Track the values each permission table claims and require them to cover
> exactly what its count declares, rejecting a count no value can reach.
> Conforming policies are unaffected.
> 
> Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy")
> Cc: [email protected]
> Signed-off-by: Bryam Vargas <[email protected]>
> Acked-by: Stephen Smalley <[email protected]>
> ---
>  security/selinux/ss/policydb.c | 51 +++++++++++++++++++++++++++++++++++++-----
>  1 file changed, 46 insertions(+), 5 deletions(-)

Merged into selinux/stable-7.2, thanks.

--
paul-moore.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.