[PATCH v3] libsepol: Validate any levels that appear in a policy

James Carter <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
Policy validation only validates levels for MLS policies, but it
is easy to create a non-mls policy with levels (just read the
policy in, change the "mls" field of the policydb to 0, and write
the policy out). A maliciously crafted non-mls policy could have
levels that cause an OOB access when processed.

Because of this, validate any levels that appear in any policy,
even if it is a non-mls policy.

Signed-off-by: James Carter <[email protected]>
Acked-by: Stephen Smalley <[email protected]>
---
v3: Fix formating

 libsepol/src/policydb_validate.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/libsepol/src/policydb_validate.c b/libsepol/src/policydb_validate.c
index fc66a4c7..4cdf0b78 100644
--- a/libsepol/src/policydb_validate.c
+++ b/libsepol/src/policydb_validate.c
@@ -1024,8 +1024,8 @@ static int validate_datum_array_entries(sepol_handle_t *handle,
 			&margs))
 		goto bad;
 
-	if (p->mls && hashtab_map(symtabs[SYM_LEVELS].table,
-				  validate_level_datum_wrapper, &margs))
+	if (hashtab_map(symtabs[SYM_LEVELS].table, validate_level_datum_wrapper,
+			&margs))
 		goto bad;
 
 	if (hashtab_map(symtabs[SYM_CATS].table, validate_datum,
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.