Commit 3e92c1e6 authored by Linus Torvalds's avatar Linus Torvalds

Merge tag 'selinux-pr-20240402' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux fix from Paul Moore:
 "A single patch for SELinux to fix a problem where we could potentially
  dereference an error pointer if we failed to successfully mount
  selinuxfs"

* tag 'selinux-pr-20240402' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: avoid dereference of garbage after mount failure
parents b1e6ec0a 37801a36
...@@ -2123,7 +2123,6 @@ static struct file_system_type sel_fs_type = { ...@@ -2123,7 +2123,6 @@ static struct file_system_type sel_fs_type = {
.kill_sb = sel_kill_sb, .kill_sb = sel_kill_sb,
}; };
static struct vfsmount *selinuxfs_mount __ro_after_init;
struct path selinux_null __ro_after_init; struct path selinux_null __ro_after_init;
static int __init init_sel_fs(void) static int __init init_sel_fs(void)
...@@ -2145,18 +2144,21 @@ static int __init init_sel_fs(void) ...@@ -2145,18 +2144,21 @@ static int __init init_sel_fs(void)
return err; return err;
} }
selinux_null.mnt = selinuxfs_mount = kern_mount(&sel_fs_type); selinux_null.mnt = kern_mount(&sel_fs_type);
if (IS_ERR(selinuxfs_mount)) { if (IS_ERR(selinux_null.mnt)) {
pr_err("selinuxfs: could not mount!\n"); pr_err("selinuxfs: could not mount!\n");
err = PTR_ERR(selinuxfs_mount); err = PTR_ERR(selinux_null.mnt);
selinuxfs_mount = NULL; selinux_null.mnt = NULL;
return err;
} }
selinux_null.dentry = d_hash_and_lookup(selinux_null.mnt->mnt_root, selinux_null.dentry = d_hash_and_lookup(selinux_null.mnt->mnt_root,
&null_name); &null_name);
if (IS_ERR(selinux_null.dentry)) { if (IS_ERR(selinux_null.dentry)) {
pr_err("selinuxfs: could not lookup null!\n"); pr_err("selinuxfs: could not lookup null!\n");
err = PTR_ERR(selinux_null.dentry); err = PTR_ERR(selinux_null.dentry);
selinux_null.dentry = NULL; selinux_null.dentry = NULL;
return err;
} }
return err; return err;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment