Re: [PATCH 3/4] selinux: reject an unclaimed class value in security_get_classes()

Paul Moore <[email protected]> Mon, 03 Aug 2026 16:03:48 -0400
Newsgroups org.kernel.vger.selinux,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Jul 31, 2026 Bryam Vargas <[email protected]> wrote:
> 
> security_get_classes() sizes an array by p_classes.nprim and fills it at
> value - 1, so a class value the policy never defines leaves a NULL.
> sel_make_classes() passes every entry to sel_make_dir(), reaching the same
> d_alloc_name() dereference as the permission array. The class symbol table
> is allowed to be sparse (policydb_class_isvalid() exists to absorb that),
> but this getter builds its own array straight from the hash table and has
> no such predicate.
> 
> Fail the lookup when a value went unclaimed instead of handing out the
> NULL. Conforming policies define every class they declare and are
> unaffected.
> 
> Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy")
> Cc: [email protected]
> Signed-off-by: Bryam Vargas <[email protected]>
> Acked-by: Stephen Smalley <[email protected]>
> ---
>  security/selinux/ss/services.c | 24 +++++++++++++++++++-----
>  1 file changed, 19 insertions(+), 5 deletions(-)

Merged into selinux/stable-7.2, thanks.

--
paul-moore.com