[PATCH] netlabel: cipso_v4: reject empty MLS level/cat lists and zero tail in cipso_v4_delopt()

sashiko-bot at kernel.org sashiko-bot at kernel.org
Sat Sep 19 22:02:48 UTC 2026


> Fix three bugs in NetLabel CIPSOv4 handling:
> 
> 1. In netlbl_cipsov4_add_std(), an empty NLBL_CIPSOV4_A_MLSLVLLST or
>    NLBL_CIPSOV4_A_MLSCATLST leaves local_size or cipso_size at 0, causing
>    kcalloc(0, ...) to return ZERO_SIZE_PTR (0x10), which bypasses NULL
>    checks and installs ZERO_SIZE_PTR arrays into cipso_v4_doi_list. Reject
>    0-sized level or category tables before allocation.
> 2. In netlbl_cipsov4_remove_cb(), also inspect NETLBL_NLTYPE_ADDRSELECT
>    entries so IPv4 address-selected domain mappings referencing a removed
>    CIPSOv4 DOI are properly cleaned up.
> 3. In cipso_v4_delopt(), zero the trailing cipso_len bytes with IPOPT_END
>    after memmove() and pass opt->opt.optlen - cipso_len to
>    cipso_v4_get_actual_opt_len() so stale tail bytes are not re-parsed.
> 
> Fixes: 96cb8e3313c7 ("[NetLabel]: CIPSOv4 and Unlabeled packet integration")
> Fixes: 389fb800ac8b ("netlabel: Label incoming TCP connections correctly in SELinux")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919215243.3472150-1-benquike@gmail.com?part=1




More information about the Linux-security-module-archive mailing list