]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
selinux: do not cancel a policy conversion that never started
authorBryam Vargas <hexlabsecurity@proton.me>
Fri, 31 Jul 2026 17:44:09 +0000 (12:44 -0500)
committerPaul Moore <paul@paul-moore.com>
Mon, 3 Aug 2026 20:03:55 +0000 (16:03 -0400)
commite5c0235a3c4e9eb047a16cd02323fe4ecf2f570e
treeeeffd25104bbbc44c284787becfa8fb259c5b323
parent28254722a459938d97150d3b0712b81e06d0645e
selinux: do not cancel a policy conversion that never started

sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes()
fails, and that helper dereferences the outgoing policy to cancel its
sidtab conversion. On the first policy load there is no outgoing policy:
security_load_policy() returns early for that case, before it converts
anything, and state->policy is still NULL. A first load that fails while
building the selinuxfs tree therefore takes a NULL dereference in
selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.

Skip the cancel when there is no old policy, mirroring the check
security_load_policy() already makes before it converts.

Cc: stable@vger.kernel.org
Fixes: 02a52c5c8c3b ("selinux: move policy commit after updating selinuxfs")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/ss/services.c