Re: [PATCH v3] libselinux: prevent ReDoS in file context regex matching
Stephen Smalley <[email protected]> Thu, 30 Jul 2026 13:23:09 -0400
| Newsgroups | org.kernel.vger.selinux |
|---|---|
| Message-ID | <CAEjxPJ6-dU+zGDQejk_uUbH=a971ZHFY2W34oM+e2+=8xfh-BA@mail.gmail.com> |
On Thu, Jul 30, 2026 at 10:05=E2=80=AFAM Petr Matyas <[email protected]>= wrote: > > The PCRE2 interpreter is susceptible to catastrophic backtracking on > crafted file context patterns or lookup keys. Since libselinux never > called pcre2_jit_compile(3), the JIT was available but unused, leaving > the interpreter exposed on all platforms. > > Fix with two complementary mitigations: > > 1. Call pcre2_jit_compile() after every pattern compilation (including > mmap deserialization) for both complete and partial matching modes. > pcre2_match() uses the JIT automatically when available, which avoids > the interpreter's susceptibility to catastrophic backtracking. > Note: pcre2_jit_match() is deliberately NOT used as it is known to > produce incorrect results on some platforms (e.g. aarch64). > > 2. Create a shared pcre2_match_context with a backtrack step limit of > 10 000 000 and pass it to pcre2_match(). PCRE2_ERROR_MATCHLIMIT is > treated as no-match to keep the lookup safe rather than failing > noisily. This bounds worst-case matching time to milliseconds for > any pattern/subject combination, regardless of JIT availability. > > The vulnerability was reproduced and confirmed fixed on: > - RHIVOS 2.0 / aarch64 > - RHEL 10.3 / x86_64 > - Fedora 44 / x86_64 > > Reproducer (149 bytes, base64): > AwovMi0GLy8GCygKeAYGKwYLKAoKCgAAAPpXKgsoCi8vBgs8PG5vbmU+PgovMi0GLy8GCygKe= AYG > KwYLKAoKCiNXLy8wCwsoCgojV1dXClcqCygKLy8vV1cueHhXV1d4eHgveCsGCygKCgonVy9XV= 3cy > eHgveAcGJAsoCi8tLwYvMi0GLy8GCzw8bm9uZT4+3q2+7y8=3D > > Signed-off-by: Petr Matyas <[email protected]> Acked-by: Stephen Smalley <[email protected]>