Re: [PATCH 3/4] selinux: reject an unclaimed class value in security_get_classes()

From: Stephen Smalley

Date: Fri Jul 31 2026 - 15:50:34 EST


On Fri, Jul 31, 2026 at 1:44 PM Bryam Vargas via B4 Relay
<devnull+hexlabsecurity.proton.me@xxxxxxxxxx> wrote:
>
> From: Bryam Vargas <hexlabsecurity@xxxxxxxxx>
>
> security_get_classes() sizes an array by p_classes.nprim and fills it at
> value - 1, so a class value the policy never defines leaves a NULL.
> sel_make_classes() passes every entry to sel_make_dir(), reaching the same
> d_alloc_name() dereference as the permission array. The class symbol table
> is allowed to be sparse (policydb_class_isvalid() exists to absorb that),
> but this getter builds its own array straight from the hash table and has
> no such predicate.
>
> Fail the lookup when a value went unclaimed instead of handing out the
> NULL. Conforming policies define every class they declare and are
> unaffected.
>
> Fixes: 55fcf09b3fe4 ("selinux: add support for querying object classes and permissions from the running policy")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Bryam Vargas <hexlabsecurity@xxxxxxxxx>

Acked-by: Stephen Smalley <stephen.smalley.work@xxxxxxxxx>