Re: [PATCH v2] audit: fix potential integer overflow in audit_log_n_string()

From: Paul Moore

Date: Thu Jul 23 2026 - 14:00:09 EST


On Jul 18, 2026 Zhan Xusheng <zhanxusheng1024@xxxxxxxxx> wrote:
>
> audit_log_n_string() computes new_len as "slen + 3" (enclosing quotes
> plus the NUL terminator) and stores it into an int, while slen is a
> size_t. For a sufficiently large slen the addition can overflow and/or
> the result be truncated when assigned to the int new_len, so the
> "new_len > avail" check can be bypassed and the subsequent
> memcpy(ptr, string, slen) can write past the skb tail.
>
> This is the same class of bug that was fixed for the hex sibling in
> commit 65dfde57d1e2 ("audit: fix potential integer overflow in
> audit_log_n_hex()"); both helpers are reached through
> audit_log_n_untrustedstring() with the same length source.
>
> Make new_len a size_t and use check_add_overflow() to catch the
> overflow, mirroring the audit_log_n_hex() fix. No functional change for
> the in-tree callers, which all pass bounded lengths.
>
> Fixes: 168b7173959f ("AUDIT: Clean up logging of untrusted strings")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Zhan Xusheng <zhanxusheng@xxxxxxxxxx>
> ---
> v2:
> - drop the unnecessary (size_t) cast on the constant (Paul Moore)
> - emit "?" instead of "\"?\"" on overflow, matching
> audit_log_n_hex() (Paul Moore)
>
> kernel/audit.c | 11 +++++++++--
> 1 file changed, 9 insertions(+), 2 deletions(-)

Merged into audit/stable-7.2 with the intent of sending this up to Linus
once it has gone through some testing. Thanks!

--
paul-moore.com