lib/assoc_array.c | 3 ++- security/keys/keyring.c | 14 ++++++++------ 2 files changed, 10 insertions(+), 7 deletions(-)
An unprivileged keyring whose keys collide through the description-chunk
path can drive assoc_array node splitting into an out-of-bounds slot write.
Patch 1 stops the out-of-bounds read in keyring_get_key_chunk(); patch 2
makes the chunk byte order agree with keyring_diff_objects(); patch 3 fixes
the shortcut-walk trim so the walk cannot be steered down the wrong
descendant.
v3 changes (patch 1 only; patches 2 and 3 are unchanged):
Per Jarkko's review, patch 1 no longer extends the existing
keyring_get_key_chunk() declaration line; the new offset is declared on its
own line as unsigned int. No functional change.
Patches 2 and 3 are unchanged from v2 and carry Jarkko's Reviewed-by.
v2: https://lore.kernel.org/keyrings/20260714115451.3773164-1-michael.bommarito@gmail.com/
v1: https://lore.kernel.org/keyrings/20260712014500.480410-1-michael.bommarito@gmail.com/
Michael Bommarito (3):
keys: fix out-of-bounds read in keyring_get_key_chunk()
keys: make keyring key-chunk byte order agree with
keyring_diff_objects()
assoc_array: trim the final shortcut word using the current chunk end
lib/assoc_array.c | 3 ++-
security/keys/keyring.c | 14 ++++++++------
2 files changed, 10 insertions(+), 7 deletions(-)
base-commit: 2c7c88a412aa6d09cd04b414211b4ef8553b5309
--
2.53.0
On Sun, Jul 19, 2026 at 12:15:02PM -0400, Michael Bommarito wrote: > An unprivileged keyring whose keys collide through the description-chunk > path can drive assoc_array node splitting into an out-of-bounds slot write. > Patch 1 stops the out-of-bounds read in keyring_get_key_chunk(); patch 2 > makes the chunk byte order agree with keyring_diff_objects(); patch 3 fixes > the shortcut-walk trim so the walk cannot be steered down the wrong > descendant. > > v3 changes (patch 1 only; patches 2 and 3 are unchanged): > Per Jarkko's review, patch 1 no longer extends the existing > keyring_get_key_chunk() declaration line; the new offset is declared on its > own line as unsigned int. No functional change. > > Patches 2 and 3 are unchanged from v2 and carry Jarkko's Reviewed-by. > > v2: https://lore.kernel.org/keyrings/20260714115451.3773164-1-michael.bommarito@gmail.com/ > v1: https://lore.kernel.org/keyrings/20260712014500.480410-1-michael.bommarito@gmail.com/ > > Michael Bommarito (3): > keys: fix out-of-bounds read in keyring_get_key_chunk() > keys: make keyring key-chunk byte order agree with > keyring_diff_objects() > assoc_array: trim the final shortcut word using the current chunk end > > lib/assoc_array.c | 3 ++- > security/keys/keyring.c | 14 ++++++++------ > 2 files changed, 10 insertions(+), 7 deletions(-) > > > base-commit: 2c7c88a412aa6d09cd04b414211b4ef8553b5309 > -- > 2.53.0 > I'm setting up the testing environment now and hopefully have final feedback within let's say "hours" (i.e. I'll do the job, and it takes what it takes). BR, Jarkko
On Wed, Jul 22, 2026 at 06:30:43PM +0300, Jarkko Sakkinen wrote:
> On Sun, Jul 19, 2026 at 12:15:02PM -0400, Michael Bommarito wrote:
> > An unprivileged keyring whose keys collide through the description-chunk
> > path can drive assoc_array node splitting into an out-of-bounds slot write.
> > Patch 1 stops the out-of-bounds read in keyring_get_key_chunk(); patch 2
> > makes the chunk byte order agree with keyring_diff_objects(); patch 3 fixes
> > the shortcut-walk trim so the walk cannot be steered down the wrong
> > descendant.
> >
> > v3 changes (patch 1 only; patches 2 and 3 are unchanged):
> > Per Jarkko's review, patch 1 no longer extends the existing
> > keyring_get_key_chunk() declaration line; the new offset is declared on its
> > own line as unsigned int. No functional change.
> >
> > Patches 2 and 3 are unchanged from v2 and carry Jarkko's Reviewed-by.
> >
> > v2: https://lore.kernel.org/keyrings/20260714115451.3773164-1-michael.bommarito@gmail.com/
> > v1: https://lore.kernel.org/keyrings/20260712014500.480410-1-michael.bommarito@gmail.com/
> >
> > Michael Bommarito (3):
> > keys: fix out-of-bounds read in keyring_get_key_chunk()
> > keys: make keyring key-chunk byte order agree with
> > keyring_diff_objects()
> > assoc_array: trim the final shortcut word using the current chunk end
> >
> > lib/assoc_array.c | 3 ++-
> > security/keys/keyring.c | 14 ++++++++------
> > 2 files changed, 10 insertions(+), 7 deletions(-)
> >
> >
> > base-commit: 2c7c88a412aa6d09cd04b414211b4ef8553b5309
> > --
> > 2.53.0
> >
>
> I'm setting up the testing environment now and hopefully have final
> feedback within let's say "hours" (i.e. I'll do the job, and it takes what
> it takes).
Good news. I got it tested. I'll push and mirror the patches to
linux-next. Once they show up there, I'll send a PR to Linus.
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
Tested-by: Jarkko Sakkinen <jarkko@kernel.org> # Done with the provided
# reproducer.
Really good work IMHO and also great example of legit use of
AI assisted patches in my books. Thank you.
BR, Jarkko
© 2016 - 2026 Red Hat, Inc.