diff options
| author | Bryam Vargas <hexlabsecurity@proton.me> | 2026-07-27 20:30:59 -0500 |
|---|---|---|
| committer | Paul Moore <paul@paul-moore.com> | 2026-07-30 16:14:50 -0400 |
| commit | 9a82dcd98b6e6e11cfd162410967951f12152528 (patch) | |
| tree | ca064eaed82465d7fbcfd2950bd9121348e8378c /tools/perf/scripts/python | |
| parent | d14b5d0e97fccd27974fedc03b903408872907fd (diff) | |
selinux: reject a class permission count below its inherited common
security_get_permissions() maps an inherited common's permissions into
an array sized by the class's own permissions.nprim, but class_read()
takes that nprim verbatim from the policy image and never checks that it
covers the common. A class that inherits a common of N permissions while
declaring a smaller nprim is accepted, and on load the common's
permissions are written past the class-sized array -- an out-of-bounds
heap write.
Reject a class whose permission count is below its inherited common's.
Well-formed policies, where the class count already includes the
inherited permissions, are unaffected.
Cc: stable@vger.kernel.org
Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'tools/perf/scripts/python')
0 files changed, 0 insertions, 0 deletions
