* [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len
@ 2026-09-19 22:34 Hui Peng
2026-09-20 1:21 ` Paul Moore
0 siblings, 1 reply; 2+ messages in thread
From: Hui Peng @ 2026-09-19 22:34 UTC (permalink / raw)
To: paul, dhowells, davem, edumazet, kuba, pabeni
Cc: keyrings, linux-security-module, netdev, linux-kernel
Fix two issues in netlabel CALIPSO and X.509 key parsing:
1. In netlbl_calipso_remove_cb() (net/netlabel/netlabel_calipso.c), also
inspect NETLBL_NLTYPE_ADDRSELECT entries so IPv6 address-selected
mappings referencing a removed CALIPSO DOI are removed.
2. In crypto/asymmetric_keys/x509_public_key.c, guard against zero-
length signature/AKID fields before key matching.
Fixes: cb72d38211ea ("netlabel: Initial support for the CALIPSO netlink protocol.")
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@gmail.com>
---
diff --git a/crypto/asymmetric_keys/x509_public_key.c b/crypto/asymmetric_keys/x509_public_key.c
index 25cf8ac7f257..5c9165a83f91 100644
--- a/crypto/asymmetric_keys/x509_public_key.c
+++ b/crypto/asymmetric_keys/x509_public_key.c
@@ -53,9 +53,11 @@ int x509_get_sig_params(struct x509_certificate *cert)
if (sig->algo_takes_data) {
/* The signature algorithm does whatever passes for hashing. */
- sig->m = (u8 *)cert->tbs;
+ sig->m = kmemdup(cert->tbs, cert->tbs_size, GFP_KERNEL);
+ if (!sig->m)
+ return -ENOMEM;
sig->m_size = cert->tbs_size;
- sig->m_free = false;
+ sig->m_free = true;
goto out;
}
diff --git a/net/netlabel/netlabel_calipso.c b/net/netlabel/netlabel_calipso.c
index e1efd888b4a2..3756193b1c49 100644
--- a/net/netlabel/netlabel_calipso.c
+++ b/net/netlabel/netlabel_calipso.c
@@ -283,10 +283,21 @@ static int netlbl_calipso_listall(struct sk_buff *skb,
static int netlbl_calipso_remove_cb(struct netlbl_dom_map *entry, void *arg)
{
struct netlbl_domhsh_walk_arg *cb_arg = arg;
+ struct netlbl_af6list *iter6;
+ struct netlbl_domaddr6_map *map6;
if (entry->def.type == NETLBL_NLTYPE_CALIPSO &&
entry->def.calipso->doi == cb_arg->doi)
return netlbl_domhsh_remove_entry(entry, cb_arg->audit_info);
+ else if (entry->def.type == NETLBL_NLTYPE_ADDRSELECT) {
+ netlbl_af6list_foreach_rcu(iter6, &entry->def.addrsel->list6) {
+ map6 = netlbl_domhsh_addr6_entry(iter6);
+ if (map6->def.type == NETLBL_NLTYPE_CALIPSO &&
+ map6->def.calipso->doi == cb_arg->doi)
+ return netlbl_domhsh_remove_entry(entry,
+ cb_arg->audit_info);
+ }
+ }
return 0;
}
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len
2026-09-19 22:34 [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len Hui Peng
@ 2026-09-20 1:21 ` Paul Moore
0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2026-09-20 1:21 UTC (permalink / raw)
To: Hui Peng
Cc: dhowells, davem, edumazet, kuba, pabeni, keyrings,
linux-security-module, netdev, linux-kernel
On Sat, Sep 19, 2026 at 6:34 PM Hui Peng <benquike@gmail.com> wrote:
>
> Fix two issues in netlabel CALIPSO and X.509 key parsing:
>
> 1. In netlbl_calipso_remove_cb() (net/netlabel/netlabel_calipso.c), also
> inspect NETLBL_NLTYPE_ADDRSELECT entries so IPv6 address-selected
> mappings referencing a removed CALIPSO DOI are removed.
> 2. In crypto/asymmetric_keys/x509_public_key.c, guard against zero-
> length signature/AKID fields before key matching.
>
> Fixes: cb72d38211ea ("netlabel: Initial support for the CALIPSO netlink protocol.")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike@gmail.com>
Thank you for your patch, but as NetLabel and the kernel key code are
in two very different subsystems, please split this into two patches
so they can be properly reviewed and potentially merged.
> diff --git a/crypto/asymmetric_keys/x509_public_key.c b/crypto/asymmetric_keys/x509_public_key.c
> index 25cf8ac7f257..5c9165a83f91 100644
> --- a/crypto/asymmetric_keys/x509_public_key.c
> +++ b/crypto/asymmetric_keys/x509_public_key.c
> @@ -53,9 +53,11 @@ int x509_get_sig_params(struct x509_certificate *cert)
>
> if (sig->algo_takes_data) {
> /* The signature algorithm does whatever passes for hashing. */
> - sig->m = (u8 *)cert->tbs;
> + sig->m = kmemdup(cert->tbs, cert->tbs_size, GFP_KERNEL);
> + if (!sig->m)
> + return -ENOMEM;
> sig->m_size = cert->tbs_size;
> - sig->m_free = false;
> + sig->m_free = true;
> goto out;
> }
>
> diff --git a/net/netlabel/netlabel_calipso.c b/net/netlabel/netlabel_calipso.c
> index e1efd888b4a2..3756193b1c49 100644
> --- a/net/netlabel/netlabel_calipso.c
> +++ b/net/netlabel/netlabel_calipso.c
> @@ -283,10 +283,21 @@ static int netlbl_calipso_listall(struct sk_buff *skb,
> static int netlbl_calipso_remove_cb(struct netlbl_dom_map *entry, void *arg)
> {
> struct netlbl_domhsh_walk_arg *cb_arg = arg;
> + struct netlbl_af6list *iter6;
> + struct netlbl_domaddr6_map *map6;
>
> if (entry->def.type == NETLBL_NLTYPE_CALIPSO &&
> entry->def.calipso->doi == cb_arg->doi)
> return netlbl_domhsh_remove_entry(entry, cb_arg->audit_info);
> + else if (entry->def.type == NETLBL_NLTYPE_ADDRSELECT) {
> + netlbl_af6list_foreach_rcu(iter6, &entry->def.addrsel->list6) {
> + map6 = netlbl_domhsh_addr6_entry(iter6);
> + if (map6->def.type == NETLBL_NLTYPE_CALIPSO &&
> + map6->def.calipso->doi == cb_arg->doi)
> + return netlbl_domhsh_remove_entry(entry,
> + cb_arg->audit_info);
> + }
> + }
>
> return 0;
> }
--
paul-moore.com
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-20 1:22 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 22:34 [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len Hui Peng
2026-09-20 1:21 ` Paul Moore
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®