[PATCH v2] ima: discard modsig on detached-data binding failure

sashiko-bot at kernel.org sashiko-bot at kernel.org
Thu Sep 24 09:05:58 UTC 2026


> ima_collect_modsig() supplies the file contents to the parsed PKCS#7
> message as detached data. If the message already contains embedded data,
> pkcs7_supply_detached_data() returns -EINVAL, but IMA discards the error.
> ima_modsig_verify() subsequently verifies that embedded data instead of
> the file being appraised.
> 
> Return binding errors and discard the modsig on failure, preserving
> ordinary hashing and security.ima appraisal. Keep digest export optional:
> ML-DSA and multiple-signer messages can still verify without it. Leave
> d-modsig empty when unavailable instead of dropping the measurement.
> Audit binding errors separately so O_DIRECT does not hide their cause.
> 
> Fixes: 15588227e086 ("ima: Collect modsig")
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean at oss.cyber.gouv.fr>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924085516.3111521-2-Jeremy.Jean@oss.cyber.gouv.fr?part=1




More information about the Linux-security-module-archive mailing list