[PATCH] smackfs: reject out-of-range IPv4 octets in netlabel writes

sashiko-bot at kernel.org sashiko-bot at kernel.org
Mon Sep 21 01:55:46 UTC 2026


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] smackfs: out-of-bounds IPv4 octet validation bypassed via integer wrap-around
--

commit 13135cde4c7fdf9b39cec7b05019b4e50745e1ad
Author: Hongjian Dai <daihongjian at kylinsec.com.cn>

smackfs: reject out-of-range IPv4 octets in netlabel writes

This commit attempts to fix a misconfiguration vulnerability in
smk_write_net4addr() where out-of-range IPv4 octets were silently wrapped by
sscanf with %hhd. It changes the sscanf format to %u and adds explicit
bounds checking before storing the address.

> diff --git a/security/smack/smackfs.c b/security/smack/smackfs.c
> index 6e62dcb36f74f..5d8bddffbabd3 100644
> --- a/security/smack/smackfs.c
> +++ b/security/smack/smackfs.c

[ ... ]

> @@ -1189,17 +1190,26 @@ static ssize_t smk_write_net4addr(struct file *file, const char __user *buf,
>  		goto free_data_out;
>  	}
>  
> -	rc = sscanf(data, "%hhd.%hhd.%hhd.%hhd/%u %s",
> -		&host[0], &host[1], &host[2], &host[3], &masks, smack);
> +	rc = sscanf(data, "%u.%u.%u.%u/%u %s",
> +		&octet[0], &octet[1], &octet[2], &octet[3], &masks, smack);
>  	if (rc != 6) {
> -		rc = sscanf(data, "%hhd.%hhd.%hhd.%hhd %s",
> -			&host[0], &host[1], &host[2], &host[3], smack);
> +		rc = sscanf(data, "%u.%u.%u.%u %s",
> +			&octet[0], &octet[1], &octet[2], &octet[3], smack);
>  		if (rc != 5) {
>  			rc = -EINVAL;
>  			goto free_out;
>  		}
>  		masks = 32;
>  	}
> +	if (octet[0] > 255 || octet[1] > 255 || octet[2] > 255 ||
> +	    octet[3] > 255) {

[Severity: Medium]
Does this still silently wrap if an input value is >= 2^32?

The kernel's sscanf implementation for %u parses into a 64-bit unsigned long
long and truncates it to a 32-bit unsigned int.

Input values like 4294967296 are silently truncated to values <= 255, which
would completely bypass this new validation check and reproduce the exact
silent-wrapping misconfiguration this patch intends to fix.

> +		rc = -EINVAL;
> +		goto free_out;
> +	}
> +	host[0] = octet[0];
> +	host[1] = octet[1];
> +	host[2] = octet[2];
> +	host[3] = octet[3];
>  	if (masks > BEBITS) {
>  		rc = -EINVAL;
>  		goto free_out;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/FFA41AC93858A96A+20260921014555.20351-1-daihongjian@kylinsec.com.cn?part=1



More information about the Linux-security-module-archive mailing list