[PATCH v2] ima: discard modsig on detached-data binding failure
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Thu Sep 24 09:05:58 UTC 2026
> ima_collect_modsig() supplies the file contents to the parsed PKCS#7
> message as detached data. If the message already contains embedded data,
> pkcs7_supply_detached_data() returns -EINVAL, but IMA discards the error.
> ima_modsig_verify() subsequently verifies that embedded data instead of
> the file being appraised.
>
> Return binding errors and discard the modsig on failure, preserving
> ordinary hashing and security.ima appraisal. Keep digest export optional:
> ML-DSA and multiple-signer messages can still verify without it. Leave
> d-modsig empty when unavailable instead of dropping the measurement.
> Audit binding errors separately so O_DIRECT does not hide their cause.
>
> Fixes: 15588227e086 ("ima: Collect modsig")
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean at oss.cyber.gouv.fr>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924085516.3111521-2-Jeremy.Jean@oss.cyber.gouv.fr?part=1
More information about the Linux-security-module-archive
mailing list