]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
keys: make keyring key-chunk byte order agree with keyring_diff_objects()
authorMichael Bommarito <michael.bommarito@gmail.com>
Sun, 19 Jul 2026 16:15:04 +0000 (12:15 -0400)
committerJarkko Sakkinen <jarkko@kernel.org>
Thu, 23 Jul 2026 15:23:39 +0000 (18:23 +0300)
keyring_get_key_chunk() loads description bytes into the index chunk low
address first, while keyring_diff_objects() numbers the first differing
bit from the low end and folds the absolute byte index into the level
without removing the inline-prefix offset the level already carries.
The two disagree on byte order and bit position, so the array can be
told two keys first differ at a bit that does not differ in the chunk
the walker uses, letting crafted descriptions collide into one node.

Load the chunk in the order keyring_diff_objects() assumes and drop the
inline-prefix length when folding the byte index into the level.  This
only changes the in-memory ordering used to place keys within a keyring;
add, search and read of non-colliding keys are unaffected.

Fixes: f771fde82051 ("keys: Simplify key description management")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20260719161505.2423935-3-michael.bommarito@gmail.com
Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org>
security/keys/keyring.c

index 085f7a743354c04fb6215001ec2b91b65b87e1fe..15bf4af8f28218ec3f12c97630d1c76939af7eca 100644 (file)
@@ -293,9 +293,10 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
                desc_len -= offset;
                if (desc_len > n)
                        desc_len = n;
+               d += desc_len;
                do {
                        chunk <<= 8;
-                       chunk |= *d++;
+                       chunk |= *--d;
                } while (--desc_len > 0);
                return chunk;
        }
@@ -376,7 +377,7 @@ same:
        return -1;
 
 differ_plus_i:
-       level += i;
+       level += i - (int)sizeof(a->desc);
 differ:
        i = level * 8 + __ffs(seg_a ^ seg_b);
        return i;