android_kernel_motorola_sm6375/security
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Pawan Gupta 91b9c23b6d smackfs: Fix use-after-free in netlbl_catmap_walk()
[ Upstream commit 0817534ff9ea809fac1322c5c8c574be8483ea57 ]

Syzkaller reported use-after-free bug as described in [1]. The bug is
triggered when smk_set_cipso() tries to free stale category bitmaps
while there are concurrent reader(s) using the same bitmaps.

Wait for RCU grace period to finish before freeing the category bitmaps
in smk_set_cipso(). This makes sure that there are no more readers using
the stale bitmaps and freeing them should be safe.

[1] https://lore.kernel.org/netdev/000000000000a814c505ca657a4e@google.com/

Reported-by: syzbot+3f91de0b813cc3d19a80@syzkaller.appspotmail.com
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Casey Schaufler <casey@schaufler-ca.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2021-11-17 09:48:28 +01:00
..
apparmor apparmor: remove duplicate macro list_entry_is_head() 2021-09-26 14:07:06 +02:00
integrity evm: mark evm_fixmode as __ro_after_init 2021-11-17 09:48:23 +01:00
keys KEYS: trusted: Fix migratable=1 failing 2021-03-04 10:26:44 +01:00
loadpin
lockdown
safesetid
selinux binder: use cred instead of task for selinux checks 2021-11-17 09:48:16 +01:00
smack smackfs: Fix use-after-free in netlbl_catmap_walk() 2021-11-17 09:48:28 +01:00
tomoyo
yama
commoncap.c security: commoncap: fix -Wstringop-overread warning 2021-05-11 14:04:16 +02:00
device_cgroup.c
inode.c
Kconfig
Kconfig.hardening
lsm_audit.c dump_common_audit_data(): fix racy accesses to ->d_name 2021-01-19 18:26:16 +01:00
Makefile
min_addr.c
security.c binder: use cred instead of task for selinux checks 2021-11-17 09:48:16 +01:00