[PATCH v2] certs: x509: duplicate cert->tbs when sig->algo_takes_data is set
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Sun Sep 20 23:59:30 UTC 2026
> In x509_get_sig_params(), when sig->algo_takes_data is true, sig->m is
> assigned (u8 *)cert->tbs with sig->m_free = false. However, cert->tbs
> points into the temporary ASN.1 buffer (prep->data) passed to
> x509_cert_parse(), while cert->sig is retained in
> prep->payload.data[asym_auth] by x509_key_preparse() after prep->data
> is freed by the caller. Subsequent signature verification on the key's
> public_key_signature dereferences the freed TBS buffer.
>
> Duplicate cert->tbs with kmemdup() and set sig->m_free = true so sig->m
> remains valid for the lifetime of struct public_key_signature.
>
> Tested in QEMU against Linux 7.3.0-rc3 with KASAN enabled by adding an
> ML-DSA-44 (OID 2.16.840.1.101.3.4.3.17) X.509 certificate via
> add_key("asymmetric", ...) and linking it into a signature-restricted
> keyring via keyctl(KEYCTL_LINK), which triggers the following KASAN
> [ ... ]
>
> Fixes: f3eccecd782d ("pkcs7: Allow the signing algo to do whatever digestion it wants itself")
> Cc: stable at vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260920235249.260530-1-benquike@gmail.com?part=1
More information about the Linux-security-module-archive
mailing list