[PATCH v3 0/3] keys: fix keyring assoc-array out-of-bounds read and index inconsistency

Jarkko Sakkinen jarkko at kernel.org
Wed Jul 22 15:30:43 UTC 2026


On Sun, Jul 19, 2026 at 12:15:02PM -0400, Michael Bommarito wrote:
> An unprivileged keyring whose keys collide through the description-chunk
> path can drive assoc_array node splitting into an out-of-bounds slot write.
> Patch 1 stops the out-of-bounds read in keyring_get_key_chunk(); patch 2
> makes the chunk byte order agree with keyring_diff_objects(); patch 3 fixes
> the shortcut-walk trim so the walk cannot be steered down the wrong
> descendant.
> 
> v3 changes (patch 1 only; patches 2 and 3 are unchanged):
> Per Jarkko's review, patch 1 no longer extends the existing
> keyring_get_key_chunk() declaration line; the new offset is declared on its
> own line as unsigned int.  No functional change.
> 
> Patches 2 and 3 are unchanged from v2 and carry Jarkko's Reviewed-by.
> 
> v2: https://lore.kernel.org/keyrings/20260714115451.3773164-1-michael.bommarito@gmail.com/
> v1: https://lore.kernel.org/keyrings/20260712014500.480410-1-michael.bommarito@gmail.com/
> 
> Michael Bommarito (3):
>   keys: fix out-of-bounds read in keyring_get_key_chunk()
>   keys: make keyring key-chunk byte order agree with
>     keyring_diff_objects()
>   assoc_array: trim the final shortcut word using the current chunk end
> 
>  lib/assoc_array.c       |  3 ++-
>  security/keys/keyring.c | 14 ++++++++------
>  2 files changed, 10 insertions(+), 7 deletions(-)
> 
> 
> base-commit: 2c7c88a412aa6d09cd04b414211b4ef8553b5309
> -- 
> 2.53.0
> 

I'm setting up the testing environment now and hopefully have final
feedback within let's say "hours" (i.e. I'll do the job, and it takes what
it takes).

BR, Jarkko



More information about the Linux-security-module-archive mailing list