Re: [stable/linux-6.18.y 2/2] selinux: fix overlayfs mmap() and mprotect() access checks
Greg KH <[email protected]> Thu, 25 Jun 2026 12:06:38 +0100
| Newsgroups | org.kernel.vger.linux-unionfs,org.kernel.vger.bpf,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-security-module,org.kernel.vger.selinux |
|---|---|
| Message-ID | <2026062529-squealing-suffice-ed61@gregkh> |
On Mon, Jun 22, 2026 at 11:14:16AM +0800, Cai Xinchen wrote: > From: Paul Moore <[email protected]> > > The existing SELinux security model for overlayfs is to allow access if > the current task is able to access the top level file (the "user" file) > and the mounter's credentials are sufficient to access the lower > level file (the "backing" file). Unfortunately, the current code does > not properly enforce these access controls for both mmap() and mprotect() > operations on overlayfs filesystems. > > This patch makes use of the newly created security_mmap_backing_file() > LSM hook to provide the missing backing file enforcement for mmap() > operations, and leverages the backing file API and new LSM blob to > provide the necessary information to properly enforce the mprotect() > access controls. > > Cc: [email protected] > Acked-by: Amir Goldstein <[email protected]> > Signed-off-by: Paul Moore <[email protected]> > Signed-off-by: Cai Xinchen <[email protected]> > --- > security/selinux/hooks.c | 242 ++++++++++++++++++++++-------- > security/selinux/include/objsec.h | 11 ++ > 2 files changed, 189 insertions(+), 64 deletions(-) Again, what is the git id? thanks, greg k-h