]> git.ipfire.org Git - people/ms/linux.git/commitdiff
apparmor: fail unpack if profile mode is unknown
authorJohn Johansen <john.johansen@canonical.com>
Thu, 19 Dec 2019 23:55:39 +0000 (15:55 -0800)
committerJohn Johansen <john.johansen@canonical.com>
Tue, 21 Jan 2020 13:58:53 +0000 (05:58 -0800)
Profile unpack should fail if the profile mode is not a mode that the
kernel understands.

Signed-off-by: John Johansen <john.johansen@canonical.com>
security/apparmor/policy_unpack.c

index 80364310fb1e0bd2c7dcb1b7dd0c7d9b121c32ec..e4e329d695278639420d807615ae9a1e7d91ab93 100644 (file)
@@ -748,10 +748,14 @@ static struct aa_profile *unpack_profile(struct aa_ext *e, char **ns_name)
                goto fail;
        if (tmp == PACKED_MODE_COMPLAIN || (e->version & FORCE_COMPLAIN_FLAG))
                profile->mode = APPARMOR_COMPLAIN;
+       else if (tmp == PACKED_MODE_ENFORCE)
+               profile->mode = APPARMOR_ENFORCE;
        else if (tmp == PACKED_MODE_KILL)
                profile->mode = APPARMOR_KILL;
        else if (tmp == PACKED_MODE_UNCONFINED)
                profile->mode = APPARMOR_UNCONFINED;
+       else
+               goto fail;
        if (!unpack_u32(e, &tmp, NULL))
                goto fail;
        if (tmp)