[PATCH] KEYS: asymmetric: fix out_len bounds check and in2_len union clobber in keyctl_pkey

sashiko-bot at kernel.org sashiko-bot at kernel.org
Sat Sep 19 22:27:43 UTC 2026


> Fix two bugs in asymmetric keyctl parameter validation:
> 
> 1. In keyctl_pkey_params_get_2() (security/keys/keyctl_pkey.c),
>    params->in2_len and params->out_len share an anonymous union.
>    Assigning params->in2_len for KEYCTL_PKEY_VERIFY after setting
>    params->out_len clobbers out_len, and info.max_data_size is checked
>    against in_len instead of out_len for encrypt/decrypt/sign
>    operations.
> 2. In software_key_determine_akcipher()
>    (crypto/asymmetric_keys/public_key.c), ensure buffer length checks
>    properly validate both input and output sizes against the key's
>    maximum size.
> 
> Fixes: 00d60fd3b932 ("KEYS: Provide keyctls to drive the new key type ops for asymmetric keys [ver #2]")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919221742.3709658-1-benquike@gmail.com?part=1




More information about the Linux-security-module-archive mailing list