From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f176.google.com (mail-qt1-f176.google.com [209.85.160.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 941AC2D8773 for ; Wed, 8 Jul 2026 18:22:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.176 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783534937; cv=none; b=rnioZH29xa0jWP6zV4/CCFgvmUq+SADwt2kGL1AG5CSU2DU6AdttQ04YiEFe4sYbca0scqTNYrOLHrUSbsD5bZr8LlnAQL0NyyCq6taGW0BZmsHNWhHjVt5zcTzvWhzRb0reveMq4lL+LVymNN9VYgYn0I5UBLrc3gH7KPx4m6o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783534937; c=relaxed/simple; bh=ET805bVdGS1zkjS8gMEQyUPVGOXKeqtwtnM/BLCiVXM=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=uHj7ghRjiwKrhuTQO7EuAfPXOT4ARuxXsiZqXi0sJ1OF0R/2ModTDrFl+pS6OOcOYOX0VabOb0XDdHVbeKpxziYTxc24T6MtHB9jiEMONL1RI5HqnV1jhSkXy6h3MUTiKjZ7voK/3QdPlf7maQYaW7Bn2+P4wdFZUatgkpVeQ5s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=PGNmTiQ5; arc=none smtp.client-ip=209.85.160.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="PGNmTiQ5" Received: by mail-qt1-f176.google.com with SMTP id d75a77b69052e-51c0006ea8eso7336111cf.1 for ; Wed, 08 Jul 2026 11:22:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1783534933; x=1784139733; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mlii6ix2M2a5zOrDQVBlUrLvKVbK3cfMDLu39vPxD1A=; b=PGNmTiQ5n/vwCvnDVh//Y1+ziX5vs+hhFjY9ebl2K1jU20YBJBBOeJ9GJ/5AvY3wV2 hUoQ1M2unNtwSmmsDUNY7HmQyL55u637YLfdu2q1uhUDz7PXHPZRvkXH5Hud9ZMqumoa Mmaw9MI5zZqymtilFU2D4u3pz8W/ylhpGhOR8+QwXZwVxShcIzH+Sqe1ORzHlcEE8ri2 scwF7/9gBG5BYabWWt1l1LrGzbxH0seMTgycug23WCK2MlyHn7wrMVoerC76VN7221fY 48qbuH1xcaoHeNBUhhq69iMIaLC8q2j9TylD3EssnuiCdFjGUY7tSH+grNHdBw23G0ja ZZqw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783534933; x=1784139733; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=mlii6ix2M2a5zOrDQVBlUrLvKVbK3cfMDLu39vPxD1A=; b=U470C3lvJUMWVW5+3pqOOh4NFP0Mw9Or2bzaDgbcG0oxK12nDm3bFRuUpP2yKNAHNk VfSh/8tr/MWYyWnDHhVhQq1A/7AN9wau3negIlv0HllYhB+2F+n61MPJeRSmRYUEwiF4 S5I4DZmREzUV6gYFT2Cl7DOIPdN1iM3mxE1YSeYLuRWkADvtGsC/yO9DM1hscYhpjgBg Q8Fm+G+Gbn/XlJ2oumtrB6hIETRPtZHxGSXgjik0zoVsXtEgNVSFMswL10cKq4hdLEEy /Q+OS9uSUkfpz+WCFVSR4CgyFkEgnFRYSaUNyqr4jZcMcjlffmivaSphY7wYSFYkkL0S kx/Q== X-Forwarded-Encrypted: i=1; AHgh+Rp12Q+HcXry66vaf9T6wxeM5c5YZi17QJ0f03NF6R/swX0sPA8xCOKOEmjFIWKlj/xzCHI5BL+jUaXzRP8=@vger.kernel.org X-Gm-Message-State: AOJu0Ywl8eu3HJcLhb428u4/Hf5yHYcLQZK8GbDPQIQZYysPfswnopG/ geOjwqbKzGuxEVqIOZjwo1l35uDmpZVZL1ekVZ1FAZ4CMIsLJ3n+tpAtaTStSYqhAQ== X-Gm-Gg: AfdE7ck7RJUGAMUesdZ+qWMGjSOp0Jn9hheKGzUQngRJx5lqnwOm1cmLrc2To996Mfa d2dT70UhEDSL2GA2i9yRvsXBFFpfas6bbUyKqBtUWjF/KlLshm3Cm9OnbDR26x0RUA44chgIf10 yuDADTUmqCuyo3zRKVRsRWP44e2OEuGGsKJ6M9ko/lhHf7QYf083tJpDj89ohxUjMWQ4ZFKBntr geUbdQ/BLPbWGG3oJ57jyXhS4g3MvhRH04sO9ZzSbFfuwJmn1FGVwIDqYcVakFOwszTBlmd8vaI 75n++kC+QgQ0/UJXYd07F/SfLn/RLLOB1m999UsM57NzQbxPL9m60SMcKPCReMYDD1GYrSWfg2h 83tXRibyEq3AzwCaz4b0Qf+/9UN3eVvwa7jcWiIZyxAtRFBuQTN5LC+pMj3XVGZIt0nYhQMyRkC vcD2BfYVj9DaDeRskz4990kf270f/2/DflC7pw/iZDMq1oSdiMc2gP4LkY4g== X-Received: by 2002:a05:620a:1994:b0:923:8612:f15 with SMTP id af79cd13be357-92ecf5c49eamr345917985a.18.1783534933540; Wed, 08 Jul 2026 11:22:13 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id af79cd13be357-92e90ba4209sm1571492185a.12.2026.07.08.11.22.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Jul 2026 11:22:08 -0700 (PDT) Date: Wed, 08 Jul 2026 14:22:07 -0400 Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260707_1504/pstg-lib:20260708_1328/pstg-pwork:20260707_1504 From: Paul Moore To: Ricardo Robaina , audit@vger.kernel.org, linux-kernel@vger.kernel.org Cc: eparis@redhat.com, Ricardo Robaina , Richard Guy Briggs Subject: Re: [PATCH v3] audit: fix potential integer overflow in audit_log_n_hex() References: <20260702140411.1021373-1-rrobaina@redhat.com> In-Reply-To: <20260702140411.1021373-1-rrobaina@redhat.com> On Jul 2, 2026 Ricardo Robaina wrote: > > The function calculates new_len as len << 1 for hex encoding. This > has two overflow risks: the shift itself can overflow when len is > large, and the result can be truncated when assigned to new_len > (declared as int) from the size_t calculation. > > Fix by using check_shl_overflow() to catch shift overflow and > changing new_len and loop counter i to size_t to prevent truncation. > > Fixes: 168b7173959f ("AUDIT: Clean up logging of untrusted strings") > Reviewed-by: Richard Guy Briggs > Signed-off-by: Ricardo Robaina > --- > Changes in v2: > - Use check_shl_overflow() instead of manual overflow check. > Changes in v3: > - Log "?" before returning when overflow detected. > > kernel/audit.c | 12 ++++++++++-- > 1 file changed, 10 insertions(+), 2 deletions(-) > > diff --git a/kernel/audit.c b/kernel/audit.c > index e1d489bc2dff..52eb3b511bad 100644 > --- a/kernel/audit.c > +++ b/kernel/audit.c > @@ -62,6 +62,7 @@ > #include > #include > #include > +#include > > #include "audit.h" > > @@ -2076,7 +2077,8 @@ void audit_log_format(struct audit_buffer *ab, const char *fmt, ...) > void audit_log_n_hex(struct audit_buffer *ab, const unsigned char *buf, > size_t len) > { > - int i, avail, new_len; > + int avail; > + size_t i, new_len; > unsigned char *ptr; > struct sk_buff *skb; > > @@ -2084,9 +2086,15 @@ void audit_log_n_hex(struct audit_buffer *ab, const unsigned char *buf, > return; > > BUG_ON(!ab->skb); > + I removed this added vertical whitespace as it wasn't really necessary and could potentially impact anyone who wants to backport this patch. Otherwise this looks good to me, so I'm going to mark it for stable and merge it via audit/stable-7.2. Thanks! > skb = ab->skb; > avail = skb_tailroom(skb); > - new_len = len<<1; > + > + if (check_shl_overflow(len, 1, &new_len)) { > + audit_log_format(ab, "?"); > + return; > + } > + > if (new_len >= avail) { > /* Round the buffer request up to the next multiple */ > new_len = AUDIT_BUFSIZ*(((new_len-avail)/AUDIT_BUFSIZ) + 1); > -- > 2.53.0 -- paul-moore.com