From nobody Sat Jul 25 03:46:05 2026 Received: from mail-qk1-f176.google.com (mail-qk1-f176.google.com [209.85.222.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2DC2526A1C4 for ; Sun, 19 Jul 2026 16:15:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477720; cv=none; b=T3pDxmUCb8TYzyJS1zop/nzVZuB3f9l069Y7x4YGHx7RzNLaJvL//Tu2FdIfdHlCoOaAnx1SnruvQ3nLZfjwcFhCiCwgqciHF7xgLmhdu93AaO9IW2EvOUaRLcYoupTlHHtl9H92B8FCtT5A8x9wEaVbEzqFZxdMoEgM05lD0J4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477720; c=relaxed/simple; bh=z7iFnYhuNkpMKfpkGAHIAltacElFBDKQMCZumHmuODE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=G9TJpxslpWdrWf4EB9/5Sz1IitIpdSllvLPdmXANBqHBVTrgRdBE0C7HXRM4pUfrVQaLF97CTBaLzqxGmrK58e7+5RCsZIv1ZrynQh0yYBkpZJXpfz1uyVmuvCTeCq57o4qNPfqX0oCdyuaYbqCMlpj3v66g4HxuODp0quKpfnM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KK10IMqq; arc=none smtp.client-ip=209.85.222.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KK10IMqq" Received: by mail-qk1-f176.google.com with SMTP id af79cd13be357-92ea24a2dbfso791744385a.0 for ; Sun, 19 Jul 2026 09:15:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477718; x=1785082518; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sv09Y2zV5fntrZQk40NqD/qbsVElT2FYKTtooq7g6h8=; b=KK10IMqq0Ej7p10MaQR4YYnt3Iv8anpcpvUcl5gj692/UEiKDpQS1VFq9657BayI47 +hXQZDKACY9YreHeZVU/JKZndADrs17BOxd9SZCyGKIkFhdRsmUZaEgX65aK4Myf7mn6 rqax2ajIFwrAttED0TN616MOl3N71WYt8lyU3JKmNHjYX5CDObZiiBHZfC11Qc25Djlu Ar4+oP5duGpP1XTqpLmgWMTHILbCWzpmUvVqsNjGs7Z/sLIQDgnDvotMkBFQjsvGwaWI ujeG+btvkJI09WANODVjSg/n7+LaDeq02T4spElnhnMRHlh4UDTHICn8FW1R6I3U++DQ SRrQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477718; x=1785082518; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=sv09Y2zV5fntrZQk40NqD/qbsVElT2FYKTtooq7g6h8=; b=AwtkgtpG2gwgebW3bD3liYcKZKfYgXdI2TlZ7dqvMfoQDrqjR/0b9P6r63oycWsyEu rr2ffNwd7wR2E0lW07qAiw1242KJK50AvNjfv3re3o4y2wCrCSGTtjwv9u88uQRhYWl5 ASBhN7YeLJGGRO/v5Zbx4b6LJcngLEb53epcPAwiPsKMEu4pbsP08PE4UvP7S54sQZZY t2YxT2vfMfhVzoub5cnIGYQq3LXk6LcQ+gc5rA8kSk44jDaTEpEsC7uOVcpZjilZNyvN 2ST1I5fabAuclxNFch7BUpbZl1LKWtbVWOek0CKDfu5uqZKPGbgd5YHdRPiWfAyrgvge HS4w== X-Forwarded-Encrypted: i=1; AHgh+Rp3awOMBjjKG7RqLFMPk109Z2sj74H4zRRZ9lLJzkeW61yu6WpausKLdk+oEiEhpwAcVyCeSoV5oCv6jHw=@vger.kernel.org X-Gm-Message-State: AOJu0YxtwZwzjoDJwVpOo50tQjoMdndu7LYgrHoa7cti8HBIjaweXlqq kHAPW5DipHEuJu9Kbr//7VjkA4cWy12xesl3fbGgtBseRQvuz58TeAGz X-Gm-Gg: AfdE7ckvYNnyShUkr0zmD2eyegAjGNbdDQw8GXOycjnxKJGMj2UjJNv66M1FMcEfyrI nq/FnNJ1ozLz/hTE7nAmou20IK4v63UoJwXr3oYBrjmc1IivehxbLxzOX0t3sIACPZwMVEPQTqJ ai71I/CUqjLRBmyWGZWxWhxtyIjZ3WsiAmLaOr4xKOy2AZCJXEp/H1JQpnX1GgkXKbylEraaJMH 1aTWs/HU+Cj22GdBkC04zouCvlM0WBd+yRoITf3y+yeIjg0tdCqXv2lO+Va+y3aqtTS6q8QYfZj 21mNbsCsfdTIdu6nRzVDbBk1dyOAgmExJAsiwcDxqY0Gmj7TCwdXEV5Aud6grrPvBfWWhPzo+Gg wtsQ10087QPWMfULYS2b6wZx9DU2V1KzqKVh/IwnJmLOJkaJXxP0swxRdgLmRxmZThTxjLGXHfl ntHekE4UT0Nb5lJ4TWV5O+7ZZJkYEw3+IjZew1MaYviEY2YcUamcmZGg5ZX6yfKIcsoxorTvmua A9t92qrRu4iYMZ+Oz5Q9zm52Pf5iMfs X-Received: by 2002:a05:620a:29c4:b0:92e:bc32:8ca7 with SMTP id af79cd13be357-930b3ef7168mr1108379385a.33.1784477717968; Sun, 19 Jul 2026 09:15:17 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-930b52fe271sm672374185a.16.2026.07.19.09.15.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Jul 2026 09:15:17 -0700 (PDT) From: Michael Bommarito To: David Howells , Jarkko Sakkinen Cc: Andrew Morton , Paul Moore , James Morris , "Serge E . Hallyn" , keyrings@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 1/3] keys: fix out-of-bounds read in keyring_get_key_chunk() Date: Sun, 19 Jul 2026 12:15:03 -0400 Message-ID: <20260719161505.2423935-2-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260719161505.2423935-1-michael.bommarito@gmail.com> References: <20260719161505.2423935-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" For description-level chunks keyring_get_key_chunk() advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description is read past its kmemdup(desc, desc_len + 1) allocation. Compute the full byte offset and bounds-check the description against it before reading. The walk only reaches a description-level chunk when two keys collide through the hash, x, type and domain_tag chunks, so this is reached from an unprivileged add_key(2) with a crafted pair of same-type keys whose index hashes collide; KASAN reports a slab-out-of-bounds read. Fixes: f771fde82051 ("keys: Simplify key description management") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael Bommarito Reviewed-by: Jarkko Sakkinen Tested-by: Jarkko Sakkinen # Done with the provided --- security/keys/keyring.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/security/keys/keyring.c b/security/keys/keyring.c index 7a2ee0ded7c93..085f7a743354c 100644 --- a/security/keys/keyring.c +++ b/security/keys/keyring.c @@ -271,6 +271,7 @@ static unsigned long keyring_get_key_chunk(const void *= data, int level) unsigned long chunk =3D 0; const u8 *d; int desc_len =3D index_key->desc_len, n =3D sizeof(chunk); + unsigned int offset; =20 level /=3D ASSOC_ARRAY_KEY_CHUNK_SIZE; switch (level) { @@ -284,12 +285,12 @@ static unsigned long keyring_get_key_chunk(const void= *data, int level) return (unsigned long)index_key->domain_tag; default: level -=3D 4; - if (desc_len <=3D sizeof(index_key->desc)) + offset =3D sizeof(index_key->desc) + level * sizeof(long); + if (desc_len <=3D offset) return 0; =20 - d =3D index_key->description + sizeof(index_key->desc); - d +=3D level * sizeof(long); - desc_len -=3D sizeof(index_key->desc); + d =3D index_key->description + offset; + desc_len -=3D offset; if (desc_len > n) desc_len =3D n; do { --=20 2.53.0 From nobody Sat Jul 25 03:46:05 2026 Received: from mail-qk1-f169.google.com (mail-qk1-f169.google.com [209.85.222.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF9AC2D2397 for ; Sun, 19 Jul 2026 16:15:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477722; cv=none; b=khGZKNhYURekuSs65Fi87GdgTqlqtSOY7Yxo62rToH69OEwRwzhwArq4oFYchUz01dZuvJaGDGCmvgFqfI93RM0E+CvU1fdXCINgz4dQCONfSOOj7/gma0dYDjUcEVoDckO8GUlSu1V1btfmPpkCvH2O1zyVtoYH/qD7v7NC50U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477722; c=relaxed/simple; bh=SEF6ayJP8+7gpjFE6bmH1rbtquW9LASsUXWTtKt0bQA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Jy1D1VyPM61NXZ/hq7ZuWwhe0OCOqNJWmmqz0fhmstvt1UnqLQdeU8N0A5urgzwfunfCUwx+4dU76dY/2kpbnxECpeVm0oGm+kSGMaYfb1g/bwZE3bpRDMuwYvuNkzYWVAdcW9FqdNndBY0ldRihl6fl9aOzCNZimsFAxG2vLv8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=bAG1Juol; arc=none smtp.client-ip=209.85.222.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="bAG1Juol" Received: by mail-qk1-f169.google.com with SMTP id af79cd13be357-92e5d50b0dbso455519285a.1 for ; Sun, 19 Jul 2026 09:15:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477719; x=1785082519; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PKH5wh89OUjevntuqAupkpsV3/CURW4CLxf9HsZImsQ=; b=bAG1JuolGv2QecX1UTOPHT9so8mA4HO+MCVJE8WCA9ucJLHdioByVdbCTd70+6RQYu ijYKNC7SWoqGlKQAtuGjyUMvWtW2Ns/L4ymo86JStPzOhErmZtg2/TumGu4uuYFf0Jj+ 2g7eaUilPWLkD6UsveyZQAXqvryHUBggrznw7T9Zcm6NNDGfY6nL2TgUt/kcNl2nvW6o wx1O+48EMH5Ek++5+NQrbm4S8dpP4jmINbsV/+Zip3WLoo3QbNQ0PMx3dOrTCmuepGZM iZL3cZyk4qhk3kYgX5azcijeKowYVcgx0z8Rlr7QcjXYvw1iM9kOWkKx/Nuf+UWHN/gM UsCg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477719; x=1785082519; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PKH5wh89OUjevntuqAupkpsV3/CURW4CLxf9HsZImsQ=; b=qY22qXnXlAlgGS64j3viv2+iagKKSD0VGyCp2iD2XbU5CVo9CgqVo0Uvmg7WQUUxSu YxGurjQvfYaMARwZOjao/LL4gVBtbxE82ED4cxVNyr1RSJZdoR7JX3dSiQNA4AIDFoFp jzTWPdqJRMGwUb6rujkfCjEg+7y2DtzwWCSgfpqNB9FsnmDy+iZjYucg57dhANYQxhOG AttpBZo8cwipvFeE4gwC5veN8JtKHrHzDToKGVgjeagxSIpiu+BRrYXlBZuzVzZ89HR1 uMBzeFCDYrBpJk6HjygkLAaXPfZnbL0Pcc+F2mOjTQMIhzSw+3Q36qy+0mkWHBn+CJCq 5bsw== X-Forwarded-Encrypted: i=1; AHgh+RoewBTUDSIerYeJalChwhZtP/33KWObo+6uvIA9wN/oWGX2UW1qFAS5sJ8E9rsQrN57Y9UbAVoe85EOpls=@vger.kernel.org X-Gm-Message-State: AOJu0YxmIT6W8eNi9pgZ91xyM9XnsY0mVTKdcBUjHQAg0WD0fMP+pK4E K+WJ2l3JQfEq4Al7U58n6Odd9qjxam84A+BudhJnAcpghRSQA2pEHdpy X-Gm-Gg: AfdE7ck5ZgqOXSa6ZvwGxDHP26OhcV+KSAr2tBUPd4CKTcxraaleLlp/wahDSa1cdzC DryCqVMCDyZwYowzKNChWceDuYeTDJ2H5T9s54Bc9TfI0jKpnZTzNk6DDqTqlEYWhNB/SFWOXKA 2nhdyRwDmNDPCT+rrdj25PYsWa8jfOK17RBpbmwYto6fzghi32PIzjh5BgZAFMMDMQH8yO9tBzd svs6xCqBJAut+38JM27U+keSQ1R8BDClQb+URWQt5pxoHRLyn5kVQl6iFR8OA0RoSUXEfQgOJoy Cl6E04CQHqKgCmsxCbW3uBU+qMN86qMxYd+B6uKKeDNDF7NORc7A/+scwltpIZUVayMCcbSXrfX yWg4GU7CnUPl7++MDi/UqdhZ2RmkCOoWLnuOMXUdZFMYdKQ0pVXpx8357yVJedhSuA5CvjqJXRG 7jTZNDFvQcrm5veBbPFqpsJQEi1E8GIQswj1GMIsaM/5auEB/ehcyf3FPvZnoW+dpXbpc2wUE9S lzISJy/c6Fg20uab3VhzQ== X-Received: by 2002:a05:620a:4483:b0:92e:dddc:6588 with SMTP id af79cd13be357-930b3ef648dmr933688585a.42.1784477719392; Sun, 19 Jul 2026 09:15:19 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-930b52fe271sm672374185a.16.2026.07.19.09.15.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Jul 2026 09:15:18 -0700 (PDT) From: Michael Bommarito To: David Howells , Jarkko Sakkinen Cc: Andrew Morton , Paul Moore , James Morris , "Serge E . Hallyn" , keyrings@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 2/3] keys: make keyring key-chunk byte order agree with keyring_diff_objects() Date: Sun, 19 Jul 2026 12:15:04 -0400 Message-ID: <20260719161505.2423935-3-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260719161505.2423935-1-michael.bommarito@gmail.com> References: <20260719161505.2423935-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" keyring_get_key_chunk() loads description bytes into the index chunk low address first, while keyring_diff_objects() numbers the first differing bit from the low end and folds the absolute byte index into the level without removing the inline-prefix offset the level already carries. The two disagree on byte order and bit position, so the array can be told two keys first differ at a bit that does not differ in the chunk the walker uses, letting crafted descriptions collide into one node. Load the chunk in the order keyring_diff_objects() assumes and drop the inline-prefix length when folding the byte index into the level. This only changes the in-memory ordering used to place keys within a keyring; add, search and read of non-colliding keys are unaffected. Fixes: f771fde82051 ("keys: Simplify key description management") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael Bommarito Reviewed-by: Jarkko Sakkinen Tested-by: Jarkko Sakkinen # Done with the provided --- security/keys/keyring.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/security/keys/keyring.c b/security/keys/keyring.c index 085f7a743354c..15bf4af8f2821 100644 --- a/security/keys/keyring.c +++ b/security/keys/keyring.c @@ -293,9 +293,10 @@ static unsigned long keyring_get_key_chunk(const void = *data, int level) desc_len -=3D offset; if (desc_len > n) desc_len =3D n; + d +=3D desc_len; do { chunk <<=3D 8; - chunk |=3D *d++; + chunk |=3D *--d; } while (--desc_len > 0); return chunk; } @@ -376,7 +377,7 @@ static int keyring_diff_objects(const void *object, con= st void *data) return -1; =20 differ_plus_i: - level +=3D i; + level +=3D i - (int)sizeof(a->desc); differ: i =3D level * 8 + __ffs(seg_a ^ seg_b); return i; --=20 2.53.0 From nobody Sat Jul 25 03:46:05 2026 Received: from mail-qk1-f171.google.com (mail-qk1-f171.google.com [209.85.222.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 20E0039F18A for ; Sun, 19 Jul 2026 16:15:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477723; cv=none; b=kaoy/6/QMTo5zNA/8mh3pxhz/V7LK6urSTlKLbCS4Af/xXL+swl+Q3thx0/PPGRwY/xi2gTKKTv9StdJnIjEX8yat0mGbg0n7S7z/eQ1WFavYTf8lW7ttKPmOsHrBb+7x0JnDmUL+tqqHYqykZ4vfN950en51v1ohOFV4zA3DJc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477723; c=relaxed/simple; bh=sLM500yHckZI96gdaqrzAndkSOc2GG8Oew7rzW2iE4w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=J5guRrYL2PvAGtLNdBq29wGdGbDsi2XTTKjTY9gU5uGa53WqUP550zxkEtqpjGkYM6Z3f33WUWSap+OvQPBd6W5cFncj5stv21F5wOboOErlZR5SlSsCwjibmcBam4Z8oPkB+6I+xH+PcDT0kRWknAWcBW3tfECUrDF4JFmhQlA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Xvi+f0tx; arc=none smtp.client-ip=209.85.222.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Xvi+f0tx" Received: by mail-qk1-f171.google.com with SMTP id af79cd13be357-92e4fd65b2bso477687185a.0 for ; Sun, 19 Jul 2026 09:15:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477721; x=1785082521; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KmGHK7gXD3QQ+rsXKqEFIuK8Q+UTYgnfH59paMrURE4=; b=Xvi+f0txlDc5DzDpvfzXZM2GfMmfNeFC4ziDGcnF6/wmYc3+ZriVkf4BDA5YKIMhUN COA0Mxn+QHkCym6Qz6XC4/o3AXMw/okLcNgUFfVylcFqbzKdQtU+ajfnsMge23sBwLgJ is7o+bUEf88J+RB0qvf91mV0RTO8DYespPcWpPjsIqb/ZLjkL3kS31HOaLtYlUrg0c8B ESp1mgE9k/ddxvWScAYrKqVaEllUzVx3i6YdvS1W4v8Z769lbIhi8XhMkjLOx1lBuLj5 vYLLiugSZkORscB2icocFl1CPEi1Z9nsZbOCW2fZ4/BJppj8ruasAfYysQxNDNxZPxv3 elvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477721; x=1785082521; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KmGHK7gXD3QQ+rsXKqEFIuK8Q+UTYgnfH59paMrURE4=; b=OIlLMcRZ4ipyDw9+jQ8NObJnrT7dZYbRuEZboK2b3Cn3dS/2TKR2e+WUB/FgiFDVJz FWj9d1VjnNbQlm0GxQxmOq2hF/g+oIHLbZ2oFhTCdtKTW4D1YHKqlHr/aQAtbh6zKK8G hzgLoQlI6+cXdb3VG6qgrfA/+aNxqx6E9Ipn70v+PRRCP4cDfgcnd8XidPy8fXJASGOh x9RD8lbG0oPeNdouk7Xnuvp2JFlN680+Rp4AJdPZ/v9RAByqG+VhfRg9nW1eUwJu2bwq kHXMXcgA6FFDqCcM7qx+EBbh005QblD8TyDKJk0PM0xJsPOC74+f2Ma7Xp/iivcr8zYF I24A== X-Forwarded-Encrypted: i=1; AHgh+RqdsHrqRpnnG5YCm66pAR2iB5LSI9Ff7HUaRAwWEdSsoYikUQ0ZrnIuR+3gACfF8HvkidJ4qhGH722TdXQ=@vger.kernel.org X-Gm-Message-State: AOJu0Ywot6VqAxSEYc9n+1a2gTMyqs+DER+kuFHMgUyHcLqGJoZSX38d JysfVumL7VHHosMbm3jFCAV2asNLxDbdNhuZI9Buj4rrphoVc4NU5yIH X-Gm-Gg: AfdE7cngLp9bMHDjUYrzEIPPrUPnxiKygAVv+hDzDWReUdZWIXdGRM56TaPriX7MOIS MaIkeJ0eZzhD3opPZFSCONIoP7i91Lb+suulS1KMCE+UbVXWcVG1CnZ6M3EBwOC7SnAeYqtb1iP Y91C8DJhGQ2kYabju01jbUX5cZDYC+YrIHQbDH/xx6TMnhzjC2GkUvhUEPERuR1fb1Un9Tj18jB dDIfv0Nzz1NRgVM3VqdTpBeaEtv2uxci7t3Ifnwrihr6+W7uekaG5mZFmjbokpVrsdXdNidj97R SX1I/4Jyxlhpa3ZgsiPWovBy+6jjleyHteUrC1okP6df5u4eL2pNqBKkgUtEfoMCEMvwm66rFCV 5VHeCt4mgI1Iq1BOq7Tc7KsR7z5imDAoZffRVgoMJCWlV/cUkyrrITaeiiOTLBmwfyQw6VMDgGw xbhuc2vEa3wFN9PvwDJq4pw9/ys8heX/WW3TqSUgpewPix5wlEjxus9yY5M4wXavx9fyWVmq7iY yQw0+6FfryRAePRFhgZ/w== X-Received: by 2002:a05:620a:19a2:b0:92b:6805:919a with SMTP id af79cd13be357-930b4353319mr1036758785a.66.1784477720740; Sun, 19 Jul 2026 09:15:20 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-930b52fe271sm672374185a.16.2026.07.19.09.15.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Jul 2026 09:15:20 -0700 (PDT) From: Michael Bommarito To: David Howells , Jarkko Sakkinen Cc: Andrew Morton , Paul Moore , James Morris , "Serge E . Hallyn" , keyrings@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 3/3] assoc_array: trim the final shortcut word using the current chunk end Date: Sun, 19 Jul 2026 12:15:05 -0400 Message-ID: <20260719161505.2423935-4-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260719161505.2423935-1-michael.bommarito@gmail.com> References: <20260719161505.2423935-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" assoc_array_walk() masks off the bits past shortcut->skip_to_level in the word that contains skip_to_level, gated on round_up(sc_level, ASSOC_ARRAY_KEY_CHUNK_SIZE) > skip_to_level. That guard is wrong in two opposite ways: - When sc_level is word-aligned (every word after the first) round_up() is a no-op, so the guard is sc_level > skip_to_level and never fires for the word that holds skip_to_level. A shortcut that spans more than one word and ends in the middle of its last word leaves that word untrimmed, and its stale high bits leak into the dissimilarity word and can steer the walk down the wrong descendant. - When sc_level is unaligned (the first word) and skip_to_level sits on the next chunk boundary, sc_level + CHUNK would exceed skip_to_level and fire the trim with shift =3D skip_to_level & CHUNK_MASK =3D=3D 0, which = clears the whole dissimilarity word and makes a differing shortcut compare equal. Use the end of the chunk that contains sc_level instead: skip_to_level < round_down(sc_level, CHUNK) + CHUNK For an aligned sc_level whose word holds skip_to_level this now fires (the first bug); for an unaligned sc_level with skip_to_level on the following boundary it does not, so shift is never 0 when the branch runs and the trim never clears the whole word. Fixes: 3cb989501c26 ("Add a generic associative array implementation.") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael Bommarito Reviewed-by: Jarkko Sakkinen Tested-by: Jarkko Sakkinen # Done with the provided --- lib/assoc_array.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/lib/assoc_array.c b/lib/assoc_array.c index bcc6e0a013eb8..b6c9723e12ced 100644 --- a/lib/assoc_array.c +++ b/lib/assoc_array.c @@ -255,7 +255,8 @@ assoc_array_walk(const struct assoc_array *array, sc_segments =3D shortcut->index_key[sc_level >> ASSOC_ARRAY_KEY_CHUNK_SH= IFT]; dissimilarity =3D segments ^ sc_segments; =20 - if (round_up(sc_level, ASSOC_ARRAY_KEY_CHUNK_SIZE) > shortcut->skip_to_l= evel) { + if (shortcut->skip_to_level < round_down(sc_level, + ASSOC_ARRAY_KEY_CHUNK_SIZE) + ASSOC_ARRAY_KEY_CHUNK_SIZE) { /* Trim segments that are beyond the shortcut */ int shift =3D shortcut->skip_to_level & ASSOC_ARRAY_KEY_CHUNK_MASK; dissimilarity &=3D ~(ULONG_MAX << shift); --=20 2.53.0