[PATCH] KEYS: asymmetric: fix out_len bounds check and in2_len union clobber in keyctl_pkey
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Sat Sep 19 22:27:43 UTC 2026
> Fix two bugs in asymmetric keyctl parameter validation:
>
> 1. In keyctl_pkey_params_get_2() (security/keys/keyctl_pkey.c),
> params->in2_len and params->out_len share an anonymous union.
> Assigning params->in2_len for KEYCTL_PKEY_VERIFY after setting
> params->out_len clobbers out_len, and info.max_data_size is checked
> against in_len instead of out_len for encrypt/decrypt/sign
> operations.
> 2. In software_key_determine_akcipher()
> (crypto/asymmetric_keys/public_key.c), ensure buffer length checks
> properly validate both input and output sizes against the key's
> maximum size.
>
> Fixes: 00d60fd3b932 ("KEYS: Provide keyctls to drive the new key type ops for asymmetric keys [ver #2]")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260919221742.3709658-1-benquike@gmail.com?part=1
More information about the Linux-security-module-archive
mailing list