]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
[PATCH] SELinux: fix an oops with NetLabel and non-MLS SELinux policy
authorPaul Moore <paul.moore@hp.com>
Fri, 19 Jan 2007 19:25:50 +0000 (14:25 -0500)
committerChris Wright <chrisw@sous-sol.org>
Mon, 5 Feb 2007 16:31:41 +0000 (08:31 -0800)
In the case where a user has configured NetLabel in the kernel but is not
using a SELinux policy with the MLS/MCS feature enabled there is a bug in
mls_export_cat() where a NULL pointer is used.  The initial problem report and
discussion can be found here (this patch has been ACK'd by Stephen Smalley and
 James Morris in the discussion thread below):

 * http://marc2.theaimsgroup.com/?t=116920302500004&r=1&w=2

This patch is specific to the 2.6.19.y kernel series as the mls_export_cat()
function has been replaced in the 2.6.20 kernel.

Signed-off-by: Paul Moore <paul.moore@hp.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Acked-by: James Morris <jmorris@namei.org>
Signed-off-by: Chris Wright <chrisw@sous-sol.org>
security/selinux/ss/mls.c

index 2cca8e251624037d3967d8fde0d21d8ed8ddf2a6..531b08a2c6cdf1d423d6a51a8692887aab4d5126 100644 (file)
@@ -641,10 +641,14 @@ int mls_export_cat(const struct context *context,
        int rc = -EPERM;
 
        if (!selinux_mls_enabled) {
-               *low = NULL;
-               *low_len = 0;
-               *high = NULL;
-               *high_len = 0;
+               if (low != NULL) {
+                       *low = NULL;
+                       *low_len = 0;
+               }
+               if (high != NULL) {
+                       *high = NULL;
+                       *high_len = 0;
+               }
                return 0;
        }