diff options
| author | Michael Bommarito <michael.bommarito@gmail.com> | 2026-07-19 12:15:03 -0400 |
|---|---|---|
| committer | Jarkko Sakkinen <jarkko@kernel.org> | 2026-07-23 18:23:32 +0300 |
| commit | 63918731f9ae25b5deb022f118e941e6dddfcef4 (patch) | |
| tree | 21967925ebcceb8aa3c00a12cd7cfd56d306ed27 /rust/zerocopy-derive/git@git.tavy.me:linux.git | |
| parent | 35d661c98fe4733490f20b4311616a3c2c30abc0 (diff) | |
keys: fix out-of-bounds read in keyring_get_key_chunk()
For description-level chunks keyring_get_key_chunk() advances the read
pointer by level * sizeof(long) past the inline prefix but only
bounds-checks the prefix, so a long enough key description is read past
its kmemdup(desc, desc_len + 1) allocation. Compute the full byte
offset and bounds-check the description against it before reading.
The walk only reaches a description-level chunk when two keys collide
through the hash, x, type and domain_tag chunks, so this is reached from
an unprivileged add_key(2) with a crafted pair of same-type keys whose
index hashes collide; KASAN reports a slab-out-of-bounds read.
Fixes: f771fde82051 ("keys: Simplify key description management")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260719161505.2423935-2-michael.bommarito@gmail.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
Diffstat (limited to 'rust/zerocopy-derive/git@git.tavy.me:linux.git')
0 files changed, 0 insertions, 0 deletions
