[PATCH] netlabel: cipso_v4: reject empty MLS level/cat lists and zero tail in cipso_v4_delopt()
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Sat Sep 19 22:02:48 UTC 2026
> Fix three bugs in NetLabel CIPSOv4 handling:
>
> 1. In netlbl_cipsov4_add_std(), an empty NLBL_CIPSOV4_A_MLSLVLLST or
> NLBL_CIPSOV4_A_MLSCATLST leaves local_size or cipso_size at 0, causing
> kcalloc(0, ...) to return ZERO_SIZE_PTR (0x10), which bypasses NULL
> checks and installs ZERO_SIZE_PTR arrays into cipso_v4_doi_list. Reject
> 0-sized level or category tables before allocation.
> 2. In netlbl_cipsov4_remove_cb(), also inspect NETLBL_NLTYPE_ADDRSELECT
> entries so IPv4 address-selected domain mappings referencing a removed
> CIPSOv4 DOI are properly cleaned up.
> 3. In cipso_v4_delopt(), zero the trailing cipso_len bytes with IPOPT_END
> after memmove() and pass opt->opt.optlen - cipso_len to
> cipso_v4_get_actual_opt_len() so stale tail bytes are not re-parsed.
>
> Fixes: 96cb8e3313c7 ("[NetLabel]: CIPSOv4 and Unlabeled packet integration")
> Fixes: 389fb800ac8b ("netlabel: Label incoming TCP connections correctly in SELinux")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260919215243.3472150-1-benquike@gmail.com?part=1
More information about the Linux-security-module-archive
mailing list