From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f173.google.com (mail-qt1-f173.google.com [209.85.160.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DD5BB3A254D for ; Thu, 30 Jul 2026 20:14:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785442494; cv=none; b=CRgDCgS6jboxk5XYlX3JbmOYsK3ETKro9+u7Wr3e/L4+wQOjLIEJDbOutmesqyYrj4kBDXQVkCTIks3KnCg9mzvHadoQjagG2Ks1LRmkbh6dsEzrKaxPoAZNb0y5eGSzORHOYis7Ticb5VETzzKyJCDE5AVNTMeqYrsIaldrG3Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785442494; c=relaxed/simple; bh=x8TKZ9jYhyzM1a5fwTtEIh8i1mL6sRUGtu3z26RYxqU=; h=Date:Message-ID:MIME-Version:Content-Type:From:To:Cc:Subject: References:In-Reply-To; b=SBIx/0b7H6gaV1/nGBu9db/MR1GLpd9C11eQkJNc5hlfNVwsF7KLkU5bqxNNoDs71g7AphEqOLPZZ4UFU5aHvHi5mCD2iYpm8iW71hglso1133lECnokKku3Fjckm+6/NKxiZyvbKn1eZnu/UsLWYbiq7/ZlCOJ/Owxkfddkk8s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com; spf=pass smtp.mailfrom=paul-moore.com; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b=cjvtZ5nG; arc=none smtp.client-ip=209.85.160.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=paul-moore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=paul-moore.com header.i=@paul-moore.com header.b="cjvtZ5nG" Received: by mail-qt1-f173.google.com with SMTP id d75a77b69052e-52b3934af3fso1671361cf.1 for ; Thu, 30 Jul 2026 13:14:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=paul-moore.com; s=google; t=1785442488; x=1786047288; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ErFUHOiSRMdlTPbbaHxtbkT76Bk1OAXPP0xUjronXc0=; b=cjvtZ5nGpQLOJ+ecv/bj68vtgxsPuoMFastpvGyH1BgqsrNVcjCkWXoVKtK0w6hXuY maoATqA1SErlppyIuJaJXSekyK89+sZwTyeipKwu1H2N2688DyxJXkqVp9vk187eaBPf uxCcns+gPqVvR219qLjjOVGOcW7zclNIqWImUsGITMMvSJnjlh+hxGUvMc3ifLwQOlzm Sglf0qtWuwg5ml5lCiG4r6PS7JU4SY75t9MpgubG0LIoyTrOhw/+vS1rDP7v0TDQPWRc ZamSHEPn2xUy3dhBEe7N9zVfvRGWyG7woPhBwQq5eNmCWEaOurFTsioeU8MEWTA2SEbU ljoQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785442488; x=1786047288; h=in-reply-to:references:subject:cc:to:from:content-transfer-encoding :content-type:mime-version:message-id:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ErFUHOiSRMdlTPbbaHxtbkT76Bk1OAXPP0xUjronXc0=; b=YBi8Jmv2AHtPvkG61nQ/iydkGPFPahpqLlij32IhdAELC1v7koKq0USl+8ZWMLCJ3E Z9bUR3NM/sQMQpwT31tCIygOlXKg9yso6vj3a9oI/LBbKuHePgXNrxiRbPM9CVp6FDU9 6iXtz7OdSKjo4Gf9K9MIRWkw3il/F2zZHKnrhC09ZKxoy0/VxEw0idj6ZRmheVhRYdUS 9NwhcNh77oMZP6cAN1RZkeIg1DGrUGZa/nz+l0Xe982DD9WJKEOk8SAifrJpZ32AHhhZ 1BsliOcSuy8Hc6S8UQzMtYXW13mU2ygk+wM2g0Sos/vwkhuDcqp2RePwd/0/x515YR9u OvEw== X-Forwarded-Encrypted: i=1; AHgh+Rr64KRnHrun0CtwB2OyuJqWeUpSby9FebHFRn5SEI57bWsonrXegCnIP28XBOc8eTcoeC266tZsN7xcX+o=@vger.kernel.org X-Gm-Message-State: AOJu0YydjvfrBr1+DE78fBQTEa3LWf4OYmOxEx7phRYgMBDhKRu3me5C o31PYX+IKXFHkCVKEfhr6z6hnT8/k4esfX8uoGJcXL01U1By1seOugI54p9KPCOf7A== X-Gm-Gg: AR+sD10M2WhiVH50vIW7FfuFhwDgJKRu9m03CBEG1ll4OFScLs6yXq08pd8zYRdBu7O tLMGxO2l7uNfFGhpIuwdiooaw+8uZktywYCN2obUjB/6JNkyCBNuVMEC9sJBD7QvnNZlDingMf5 jsyZM+2KEBwGkchX7bWGq60iRnuHm+jNeLvOqpAUS0902WQryudSzTnK03t7fKla8lGGsLRQfe0 9EOg/W5c8JzKy/ZcujBYOM/rxgeBO6QgaEcLp0XwN8YuiNbdUg3hChkJP4dgS7U7JNfObiSAeTh LA3exYdHtYuFuhX0Tw7Ai57h08xxLfzbTtSznUGFYIA403ac9sQHacexyCJ5C67hiJY0xi/AIMl hBDxBR9k5VRNKzfvvH/kETtPe+PA58uCe8GL7VHCCSCNw35dClSGmhGjA6H3tTu1VxqEURXhMqO RVOzQqy+df8Zwcb/ohqpIdN0mUNcIg7ujm+c8Wn6BtvucnsNdSkVdJjFIEF7E2kT+TrXRRF+qqc 4IY6WLyj2Aa943HW9caCYfg2Xu+kvNdIeYwA4bWoeyH0w== X-Received: by 2002:ac8:5f91:0:b0:51a:8b64:69e0 with SMTP id d75a77b69052e-52b38378d06mr41052831cf.11.1785442488016; Thu, 30 Jul 2026 13:14:48 -0700 (PDT) Received: from localhost (pool-71-126-255-178.bstnma.fios.verizon.net. [71.126.255.178]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-908325186b7sm25096636d6.43.2026.07.30.13.14.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 13:14:47 -0700 (PDT) Date: Thu, 30 Jul 2026 16:14:46 -0400 Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Mailer: pstg-pwork:20260729_1758/pstg-lib:20260730_1437/pstg-pwork:20260729_1758 From: Paul Moore To: Bryam Vargas , Stephen Smalley Cc: Kees Cook , Ondrej Mosnacek , =?utf-8?q?Christian_G=C3=B6ttsche?= , selinux@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH v2 1/2] selinux: reject a permission value exceeding the class permission count References: <20260727-b4-disp-eed1276a-v2-1-82d58cf5f882@proton.me> In-Reply-To: <20260727-b4-disp-eed1276a-v2-1-82d58cf5f882@proton.me> On Jul 27, 2026 Bryam Vargas wrote: > > perm_read() bounds a permission value by SEL_VEC_MAX but never by the > nprim of the owning class or common, which is taken verbatim from the > policy image. security_get_permissions() then writes perms[value - 1] > into an nprim-sized kcalloc() array, so a class declaring fewer > permissions than its largest permission value drives an out-of-bounds > heap write. The top-level symbol tables are validated this way; the > nested per-class permission table is not. > > Reject a permission whose value exceeds nprim, which is already set when > perm_read() runs. Well-formed policies are unaffected. > > Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy") > Cc: stable@vger.kernel.org > Signed-off-by: Bryam Vargas > Acked-by: Stephen Smalley > --- > security/selinux/ss/policydb.c | 3 +++ > 1 file changed, 3 insertions(+) Merged into selinux/stable-7.2, thanks! -- paul-moore.com