Re: [PATCH v2 2/2] selinux: reject a class permission count below its inherited common

From: Paul Moore

Date: Thu Jul 30 2026 - 16:24:02 EST


On Jul 27, 2026 Bryam Vargas <hexlabsecurity@xxxxxxxxx> wrote:
>
> security_get_permissions() maps an inherited common's permissions into
> an array sized by the class's own permissions.nprim, but class_read()
> takes that nprim verbatim from the policy image and never checks that it
> covers the common. A class that inherits a common of N permissions while
> declaring a smaller nprim is accepted, and on load the common's
> permissions are written past the class-sized array -- an out-of-bounds
> heap write.
>
> Reject a class whose permission count is below its inherited common's.
> Well-formed policies, where the class count already includes the
> inherited permissions, are unaffected.
>
> Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Bryam Vargas <hexlabsecurity@xxxxxxxxx>
> Acked-by: Stephen Smalley <stephen.smalley.work@xxxxxxxxx>
> ---
> security/selinux/ss/policydb.c | 12 ++++++++++++
> 1 file changed, 12 insertions(+)

Merged into selinux/stable-7.2, thanks!

--
paul-moore.com