From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f44.google.com (mail-qv1-f44.google.com [209.85.219.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C876F379EC6 for ; Tue, 14 Jul 2026 11:54:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784030098; cv=none; b=uLsg5IIfb1/F5FES2TRMG7y77Qki5+WcIntLC9FrtXkTlUMHu926BnGoxLm4/lLfby2fnTIeZvn39dBH4+tG7fv/sWOIf/3dfYtaNm2Fmv8UourPx0DORnKfWyy/aiSDwLdVYhXW4YUQZ4OqmRrBPewJGr2VQ4QKBqk4lBLMe54= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784030098; c=relaxed/simple; bh=4U8q91HPFoRFicOXzoAa63H08lLHbCXfw11y7FazoPI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=K4Bjx9bNT48+uZcWC+pilfhMPFbye+y18w6HNRwaQyahn9/q/hgKHEXvpIy70sRu7zd5Kc36YiDWDhCM1qYsOp6NIH5bmIJMoicX7/yHBUg0Vs3aSHsUbfZ7Sx8ca729Nej1fjoZlquAhrZB59xr76VyUjySGLpR5T4i8bKQCgE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ojC3dWLT; arc=none smtp.client-ip=209.85.219.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ojC3dWLT" Received: by mail-qv1-f44.google.com with SMTP id 6a1803df08f44-8efcfdb2b43so35468206d6.3 for ; Tue, 14 Jul 2026 04:54:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784030096; x=1784634896; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=l7ADB8De/whZT8e+EWVqNZCd354WcrnrJ/amnwN8jVI=; b=ojC3dWLTfIAjG8tQjrw+5rUHqwlVF2Wn7EC3GI6jfsOwfBTgQ5o3k317l1coVsTyn+ ZM5pwzr9GYSdc3UHrzRMfxnzI9xREvZ5FFY73O+iNZ1y2917uqMi9gK2qk2PXwacz3Bs m1LjVgm9upyxV1xt0EgC4WmtUpdPVfHdC/kKd2V3bLuV/8PTLSzeOlrOtGhpUwuVGH8m YYN1TbD4f2VP5A3YpOJn8c8FavIIUFz21ZZ3Aae/riqy86av7dS+7xyrQkCrBg61Iack 2pwPqbPADt3kbaFpBc5FCuaTUmjBBuecAV9pFiyHatiMy72MAq7mhMxvYsJQyQchisuY GslQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784030096; x=1784634896; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=l7ADB8De/whZT8e+EWVqNZCd354WcrnrJ/amnwN8jVI=; b=Ig+/RLfFMfiChfvntENmMZ8pH6RLb9l6fdflIL7FDedqG74BtqMKQMLfWxrb+n5izD ZXdIfbFMo+M6zPfHe9t6MYtrCjB/xACg8klwKL1qTF05qOLxRhci1oIvHx7BrPtNLNmV seVr1I6ovUU4bc6kBNdPlIP5j8nX4bqS9gmpulBYO35ThJIzXlRN9WcvFIgVc/y9LH5i KY6zpLNFcfWuadL4murLZRHaATRzaskKm+NGVzlL3Vp5wYiQ+eL4cf5KsT8C6ZGGlME+ mbJMfb8YGi0Sr5NbLEX5QBiLmzNMr4YbBd7gnbF2/KmloVkuD3k2kXW/LdaPMcF0VvFA gLbg== X-Forwarded-Encrypted: i=1; AHgh+RqcdcX1pubNRvFNKfT8PtlWaOzMgEL05zPi4kGsxPYM2EdTqNX0YSUzKuvthw5j+pYIZ88MdkSJNh+TTfA=@vger.kernel.org X-Gm-Message-State: AOJu0YwcXKLhyCntHbF14cMAQi9wUEe4QDRNhnHn5b5O71pziwlVxxtk plt/mBw0JAmL83ANgJ9MXwnatpe9qKngqQRp6vMX2EGd1Q87OHHqjgqL X-Gm-Gg: AfdE7cnwcswJSOWeUenvqbZ1PI/79vwS/j3dySzGBW6oWUVXeZNDWbiXf20TuZnxMjM yK/k/fNfIs2J+15fPx/2SJRDfYOh0oBv5VXKYDEFYwekMa+2VhlSNNsw0dAx/eHwp3EEXxMneMz FmXg8R4CT3NfHBGk7L3xsVzGORy10toxqCq0CPaG5+ya1ADNVJZvbJUs9qFmts2RsRM38rTkd/Z Irq5j02UHJonFudO4iCmP7zjEULFOkwU3Blfgzby94PIxEwnwien+0BmBsphCXruIBibEqTUljk uq81OFmQnztqZ4ooKaNEMiKIzX8br1e+h2zsENVY/FCzrkrEVMFv1V5aqcDQkiYsg0fhZGcDk+T DD7fYmMbfhboWueYBzTilPjPvBbXE6c1L97C+s2SFPcaz19AFYYZ4halJu8udR7zpuD3+27kD7D YlUfYETltk6T+p1xvHELhAYB7Ms+FTKjWhiC6XH2tebFpSx4IfxWYWbpaDEr5yjp2JjOKs+uF3S VTofDNUJQ== X-Received: by 2002:ac8:5ad2:0:b0:51c:1967:5098 with SMTP id d75a77b69052e-51cbf147113mr127640941cf.38.1784030095442; Tue, 14 Jul 2026 04:54:55 -0700 (PDT) Received: from server0 (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8ffd80fd492sm185100576d6.34.2026.07.14.04.54.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 Jul 2026 04:54:55 -0700 (PDT) From: Michael Bommarito To: David Howells , Jarkko Sakkinen Cc: Andrew Morton , Paul Moore , James Morris , "Serge E . Hallyn" , keyrings@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency Date: Tue, 14 Jul 2026 07:54:48 -0400 Message-ID: <20260714115451.3773164-1-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit An unprivileged keyring whose keys collide through the description-chunk path can drive assoc_array node splitting into an out-of-bounds slot write. Patch 1 stops the out-of-bounds read in keyring_get_key_chunk(); patch 2 makes the chunk byte order agree with keyring_diff_objects(); patch 3 fixes the shortcut-walk trim so the walk cannot be steered down the wrong descendant. v2 changes (patch 3 only; patches 1 and 2 are unchanged): As sashiko pointed out, the v1 patch-3 guard (sc_level + CHUNK > skip_to_level) fixed the word-aligned leak but wrongly fired for an unaligned first word whose skip_to_level sits on the next chunk boundary: shift = skip_to_level & CHUNK_MASK is then 0 and the trim clears the whole dissimilarity word, making a differing shortcut compare equal. v2 keys the trim on the end of the chunk that contains sc_level, round_down(sc_level, CHUNK) + CHUNK, which matches a brute-force oracle over every sc_level/skip_to_level pair; the original round_up guard and the v1 guard each disagree with the oracle in one regime. v1: https://lore.kernel.org/keyrings/20260712014500.480410-1-michael.bommarito@gmail.com/ Michael Bommarito (3): keys: fix out-of-bounds read in keyring_get_key_chunk() keys: make keyring key-chunk byte order agree with keyring_diff_objects() assoc_array: trim the final shortcut word using the current chunk end lib/assoc_array.c | 3 ++- security/keys/keyring.c | 15 ++++++++------- 2 files changed, 10 insertions(+), 8 deletions(-) -- 2.53.0