diff options
| author | Bryam Vargas <hexlabsecurity@proton.me> | 2026-07-31 12:44:12 -0500 |
|---|---|---|
| committer | Paul Moore <paul@paul-moore.com> | 2026-08-03 16:03:57 -0400 |
| commit | a93d37a09b863810653f93d371fb197457d59deb (patch) | |
| tree | 173cb204f90d70fc840cb13e06cc3bc74b901ccd /tools/perf/scripts/python/stackcollapse.py | |
| parent | 22b05fec62c0fe9864cfceb52f7d0f3a34d9b1dd (diff) | |
selinux: require every boolean value to be defined
p_bools.nprim comes from the policy image independently of how many
booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at
value - 1, so a count larger than the values present leaves NULL entries.
Every user of that array then walks it by index and dereferences each
entry: cond_evaluate_expr() on the access-vector path,
security_get_bools() and security_get_bool_value() behind selinuxfs, and
security_set_bools(). A sparse class value is absorbed by
policydb_class_isvalid() and its siblings; booleans have no such
predicate, and no consumer that could use one.
Reject a boolean value that no boolean defines, once, where the array is
built. Conforming policies define every boolean they declare and are
unaffected.
Cc: stable@vger.kernel.org
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'tools/perf/scripts/python/stackcollapse.py')
0 files changed, 0 insertions, 0 deletions
