From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f178.google.com (mail-qt1-f178.google.com [209.85.160.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7FAC93B95FD for ; Thu, 30 Jul 2026 20:14:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785442498; cv=none; b=VbjzfnXFBIpKFj8ISv3ZuWYlWgxnigmDVudUOW0cD696EKEoFpJDaklNLgas4Dj2haJl704JzhPAwQE3s9yUIa9VPpJUeaRi3ReWbEdDosoABS1tmrxEZ6HtKTf7nOMXoIX+WjwwRbTJeJriaeXPUUJTKVKKRiusP5KLu8Oy4RE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785442498; c=relaxed/simple; bh=vHcDygPqhdBtu2zJ4o5xxqMzLlUyOEqyaHvavKPGr7U=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=QOgGYQfq36eIVhg2+Qf0t2PjnkyHZwSH8+ZCH9tltkcLVqH3FnPXJ3Dm1nOqeY3kyyIKwgLxb/qgaGgTVvqlZyrjcTZuuqKUma5FGidV/9mzrA/oghY5nvdmQQUNFDyzJzS2+rmM/q/BbRz4oR1P35rSonjdxe8DKXqIZkDIU2w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=YeCTy7OQ; arc=none smtp.client-ip=209.85.160.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="YeCTy7OQ" Received: by mail-qt1-f178.google.com with SMTP id d75a77b69052e-51c4436d02cso1000711cf.1 for ; Thu, 30 Jul 2026 13:14:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1785442489; x=1786047289; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jNzYWcuApQUfPM28AwNebBubGci2ntfBO/GAHnoi8nc=; b=YeCTy7OQMJznhFU/5UC+rAB1urv9eeCkTTqi3ZiY422RYDyxRfVIq0l27lLx6YK5SB nPyoro37vUkGpTuxIem4gRamvsfOmQVkMkcnxRbu74jHcaFDzlV74khrofr5plXhj7IH nQcpq5BsKqBpFaOmerVQ9dZHefOZlfEXVTXEY1g/KMqs/GXACUkvSvq1jBAhu7136kIN 3cNhxVJD2CvNm5tcENiAbonfZOXycKc6232IabJyb1dhvpdTV+bfuXTGB1XhUsKdCcBm tXpAzpdex0TqttjT6V1S9V6MBfs1X+4RNWbRhVbWQT7RDKwK1DkxpvAZp7yZGilJJP1h 8reg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785442489; x=1786047289; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jNzYWcuApQUfPM28AwNebBubGci2ntfBO/GAHnoi8nc=; b=EGhGIU/XDI69x1jrK2jwrH5OPFdx84crh0g7HMs6cP/UBE9aSca5RJe2ak5DP02JTg ArvhB+nPi60kNi7KgExIb5M9rFC4ITZw2FTy4IioGzBtW4TqMOM6MxsTncAKooSxmi5U Gpne980gLWCq8yGXx0w/qBUO0WMCIMvvoKLU6NLILTqhwCQs+10UBIKiOTGIhic1YG9A T6Tzt2vxi7Js2Nv0hSyrkC+w6Ijs6OORJHfD8cQFqSDy4Tn4GwVHSIERb29cIHsf4u+b Mql0iw5y0IItN6CYwYqQSPOSUFNRWgApqfcLyoO65shKS2SvzzWw+c49/hIotZSEw8dd JaDA== X-Forwarded-Encrypted: i=1; AHgh+Rr4QJAT99dQQtp/KfIs6SZtglRCQG4V99+F5dM3f0ztDkSfxDT8Ta5QKycEoFjT2jniIZBhLWMPa8Mw1Ss=@vger.kernel.org X-Gm-Message-State: AOJu0YyJnU9OLBaIg7qGMpf0ZrvmXrhU8x6Gfx+YqoPvzMTyIMY/KewI vjx/N7CumX3+21prKCF26VwhdyxEwyRlW4aDSU2ejXpJ3bM8u+NkXBjmJKFSG5N0XQ== X-Gm-Gg: AR+sD10rhaUtPp5eVMMtFMl9uotCIjx6FWB8gDdrYe0XLnl83XFeIvTQmdTG3ltz/xD I1JkjCFi9FD3OLCbhah7rC1I17GSjkz2Sczw0ohapb8fTYPShWGpF5ImZuV8OWU5g3ZNHBUVD8W TTo+wrn+P5gNjM3ZKkhQqSA7Koo89qgp8lHghiz04M8RgKnE/YzqjG0zAx3LZa8h2v8uNw/j2XZ QXTOGarXjLZob8ed5NDS+NJj3+af6knzng/HRqx6ut5RsX5oO0EUz6hd66D3PzQnt/pHviZBm5q vSBAqzCNPDqpRO4CujwtksapTYIAEmR4BLI53n/SQppmN0WOSjshuaKfdKKdVQ9qnI3B4XDqEsQ 6cnxHeNbP1ULKnAygfVaUrmzJnzceGo59IN7SEks1+pYvXhanrPs65pDKOEEYakRW1xcwNvjAi7 B9cshWvFRRyjgYyXDTK7j4MPbpp5b1VWCNz/YNwai7pz0cemjMJGPI9bZ0fCU256TIJ84ZhYAOP HNuvFs6nLOxSTBfIKEZbMBXRWRAI3SaZQ== X-Received: by 2002:a05:622a:5c1b:b0:51c:12bf:d4a6 with SMTP id d75a77b69052e-52b38661f9dmr44260311cf.48.1785442489527; Thu, 30 Jul 2026 13:14:49 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529e2d826fbsm47640891cf.14.2026.07.30.13.14.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 13:14:48 -0700 (PDT) Date: Thu, 30 Jul 2026 16:14:48 -0400 Message-ID: <0e717a3fd2a6e59b91aa4d15efde7caf@paul-moore.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260729_1758/pstg-lib:20260730_1437/pstg-pwork:20260729_1758 From: Paul Moore To: Bryam Vargas , Stephen Smalley Cc: Kees Cook , Ondrej Mosnacek , =?utf-8?q?Christian_G=C3=B6ttsche?= , selinux@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH v2 2/2] selinux: reject a class permission count below its inherited common References: <20260727-b4-disp-eed1276a-v2-2-82d58cf5f882@proton.me> In-Reply-To: <20260727-b4-disp-eed1276a-v2-2-82d58cf5f882@proton.me> On Jul 27, 2026 Bryam Vargas wrote: > > security_get_permissions() maps an inherited common's permissions into > an array sized by the class's own permissions.nprim, but class_read() > takes that nprim verbatim from the policy image and never checks that it > covers the common. A class that inherits a common of N permissions while > declaring a smaller nprim is accepted, and on load the common's > permissions are written past the class-sized array -- an out-of-bounds > heap write. > > Reject a class whose permission count is below its inherited common's. > Well-formed policies, where the class count already includes the > inherited permissions, are unaffected. > > Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy") > Cc: stable@vger.kernel.org > Signed-off-by: Bryam Vargas > Acked-by: Stephen Smalley > --- > security/selinux/ss/policydb.c | 12 ++++++++++++ > 1 file changed, 12 insertions(+) Merged into selinux/stable-7.2, thanks! -- paul-moore.com