Re: [PATCH] libsepol: Add overflow checks when linking file and netfilter contexts

Stephen Smalley <[email protected]> Fri, 24 Jul 2026 15:56:08 -0400
Newsgroups org.kernel.vger.selinux
Message-ID <CAEjxPJ7O4gO2cCYVsqrxpsN4cNHpMEi88HTNTM6c+bU5Ncs2aQ@mail.gmail.com>
On Fri, Jul 24, 2026 at 3:28 PM James Carter <[email protected]> wrote:
>
> Use __builtin_add_overflow() when calculating the total length
> of all the file and netfilter contexts.
>
> Signed-off-by: James Carter <[email protected]>

Acked-by: Stephen Smalley <[email protected]>

> ---
>  libsepol/src/module.c | 6 ++++--
>  1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/libsepol/src/module.c b/libsepol/src/module.c
> index 5fcf5870..8aaa693d 100644
> --- a/libsepol/src/module.c
> +++ b/libsepol/src/module.c
> @@ -249,7 +249,8 @@ static int link_file_contexts(sepol_module_package_t *base,
>
>         fc_len = base->file_contexts_len;
>         for (i = 0; i < num_modules; i++) {
> -               fc_len += modules[i]->file_contexts_len;
> +               if (__builtin_add_overflow(fc_len, modules[i]->file_contexts_len, &fc_len))
> +                       return -1;
>         }
>
>         if ((s = (char *)realloc(base->file_contexts, fc_len)) == NULL) {
> @@ -281,7 +282,8 @@ static int link_netfilter_contexts(sepol_module_package_t *base,
>
>         base_nc_len = base->netfilter_contexts_len;
>         for (i = 0; i < num_modules; i++) {
> -               base_nc_len += modules[i]->netfilter_contexts_len;
> +               if (__builtin_add_overflow(base_nc_len, modules[i]->netfilter_contexts_len, &base_nc_len))
> +                       return -1;
>         }
>
>         if ((base_context = (char *)realloc(base->netfilter_contexts,
> --
> 2.55.0
>