linux/security/apparmor
Hyunwoo Kim 9f1e40193e apparmor: fix out-of-bounds write when null terminating a label vec
aa_vec_unique() null terminates at vec[n - dups] when VEC_FLAG_TERMINATE
is passed. If the components are all distinct no duplicates are dropped,
dups is 0 and the terminator goes to vec[n], so the caller has to provide
room for n + 1 entries.

aa_label_strn_parse() sets up its vector with vec_setup(profile, vec, len,
gfp) and then calls aa_vec_unique(vec, len, VEC_FLAG_TERMINATE), but
vec_setup() does not reserve the terminator entry. Up to LOCAL_VEC_ENTRIES
it uses the local array of LOCAL_VEC_ENTRIES pointers, above that it
allocates exactly len pointers. The terminator therefore lands one entry
past the end of the local array when len is LOCAL_VEC_ENTRIES, and one
entry past the end of the allocation when len is larger.

len comes from the number of "//&" separated components in the label name
and label_count_strn_entries() does not bound it. An unprivileged task
reaches the parse by writing to /proc/self/attr/apparmor/current or through
lsm_set_self_attr(2), both of which go through do_setattr(), and the name
is parsed before the change_profile permission is checked.
The query_label() path behind the securityfs .access file, which is
mode 0666, performs no permission check at all. Every component has to
resolve to a loaded profile, so a system with policy loaded is required.

The other two VEC_FLAG_TERMINATE users work on a label vec that
aa_label_alloc() has already sized with "+ 1 for null terminator entry on
vec". Reserve the same entry in vec_setup() and DEFINE_VEC(). Passing
len + 1 from the caller instead would move len == LOCAL_VEC_ENTRIES out of
the local array and into kzalloc().

Fixes: f1bd904175 ("apparmor: add the base fns() for domain labels")
Cc: stable@vger.kernel.org
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: John Johansen <john.johansen@canonical.com>
2026-08-10 16:55:11 -07:00
..
include apparmor: fix out-of-bounds write when null terminating a label vec 2026-08-10 16:55:11 -07:00
.gitignore .gitignore: add SPDX License Identifier 2020-03-25 11:50:48 +01:00
.kunitconfig apparmor: add .kunitconfig 2026-02-01 12:01:19 -08:00
af_unix.c apparmor: optimize current_label_crit_section() with needput 2026-08-07 19:15:31 -07:00
apparmorfs.c apparmor: optimize current_label_crit_section() with needput 2026-08-07 19:15:31 -07:00
audit.c apparmor: use SEND_SIG_NOINFO instead of NULL in aa_audit() 2026-08-06 13:50:45 -07:00
capability.c apparmor: transition from a list of rules to a vector of rules 2025-07-20 02:31:06 -07:00
crypto.c apparmor: move initcalls to the LSM framework 2025-10-22 19:24:27 -04:00
domain.c apparmor: make include headers self-contained 2026-06-29 10:26:36 -07:00
file.c apparmor: fix uninitialised pointer passed to audit_log_untrustedstring() 2026-06-13 20:20:13 -07:00
ipc.c apparmor: transition from a list of rules to a vector of rules 2025-07-20 02:31:06 -07:00
Kconfig apparmor: Fix build failure when ZSTD_DECOMPRESS is not enabled 2026-07-30 06:42:58 -07:00
label.c apparmor: leverage audit_log_n_untrustedstring() when possible 2026-07-20 19:07:03 -07:00
lib.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
lsm.c apparmor: optimize current_label_crit_section() with needput 2026-08-07 19:15:31 -07:00
Makefile apparmor: make all generated string array headers const char *const 2025-05-25 20:15:01 -07:00
match.c apparmor: propagate -ENOMEM correctly in unpack_table 2026-06-13 20:14:06 -07:00
mount.c apparmor: change fn_label_build() call to not return NULL 2026-06-13 20:14:07 -07:00
net.c apparmor: optimize current_label_crit_section() with needput 2026-08-07 19:15:31 -07:00
nulldfa.in apparmor: cleanup add proper line wrapping to nulldfa.in 2018-02-09 11:30:01 -08:00
path.c apparmor: Fix string overrun due to missing termination 2026-04-22 20:09:05 -07:00
policy_compat.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
policy_ns.c apparmor: fix: limit the number of levels of policy namespaces 2026-03-09 16:05:43 -07:00
policy_unpack_test.c + Features 2025-08-04 08:17:28 -07:00
policy_unpack.c apparmor: fix integer overflow in verify_tags() bounds check 2026-08-09 22:20:16 -07:00
policy.c apparmor: Initial support for compressed policies 2026-06-29 10:27:02 -07:00
procattr.c apparmor: aa_getprocattr free procattr leak on format failure 2026-06-13 20:18:30 -07:00
resource.c apparmor: fix rlimit for posix cpu timers 2026-01-29 01:27:54 -08:00
secid.c lsm: secctx provider check on release 2024-12-04 14:59:57 -05:00
stacksplitdfa.in apparmor: use the dfa to do label parse string splitting 2018-02-09 11:30:01 -08:00
task.c apparmor: fix cred UAF caused by begin_current_label_crit_section() 2026-08-06 16:15:33 -07:00