[PATCH v2] libsepol: Validate any levels that appear in a policy

James Carter <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
Policy validation only validates levels for MLS policies, but it
is easy to create a non-mls policy with levels (just read the
policy in, change the "mls" field of the policydb to 0, and write
the policy out). A maliciously crafted non-mls policy could have
levels that cause an OOB access when processed.

Because of this, validate any levels that appear in any policy,
even if it is a non-mls policy.

Signed-off-by: James Carter <[email protected]>
---
v2: - Old subject line "libsepol: Non-mls polcies should not have any levels"
    no longer fits.
    - Don't differentiate between mls and non-mls policies just validate any
    levels that are in the policy

 libsepol/src/policydb_validate.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/libsepol/src/policydb_validate.c b/libsepol/src/policydb_validate.c
index fc66a4c7..ea53da86 100644
--- a/libsepol/src/policydb_validate.c
+++ b/libsepol/src/policydb_validate.c
@@ -1024,8 +1024,8 @@ static int validate_datum_array_entries(sepol_handle_t *handle,
 			&margs))
 		goto bad;
 
-	if (p->mls && hashtab_map(symtabs[SYM_LEVELS].table,
-				  validate_level_datum_wrapper, &margs))
+	if (hashtab_map(symtabs[SYM_LEVELS].table,
+			validate_level_datum_wrapper, &margs))
 		goto bad;
 
 	if (hashtab_map(symtabs[SYM_CATS].table, validate_datum,
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.