selinux: initialize structures
authorWilliam Roberts <william.c.roberts@intel.com>
Tue, 23 Aug 2016 20:49:24 +0000 (13:49 -0700)
committerPaul Moore <paul@paul-moore.com>
Mon, 29 Aug 2016 23:22:10 +0000 (19:22 -0400)
libsepol pointed out an issue where its possible to have
an unitialized jmp and invalid dereference, fix this.
While we're here, zero allocate all the *_val_to_struct
structures.

Signed-off-by: William Roberts <william.c.roberts@intel.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/ss/policydb.c

index 992a315308258724099f05f9fbca0e9e7f12cc89..4b243855ed7b0f34aa13407ae6a2fb346e0b2012 100644 (file)
@@ -541,21 +541,21 @@ static int policydb_index(struct policydb *p)
 
        rc = -ENOMEM;
        p->class_val_to_struct =
-               kmalloc(p->p_classes.nprim * sizeof(*(p->class_val_to_struct)),
+               kzalloc(p->p_classes.nprim * sizeof(*(p->class_val_to_struct)),
                        GFP_KERNEL);
        if (!p->class_val_to_struct)
                goto out;
 
        rc = -ENOMEM;
        p->role_val_to_struct =
-               kmalloc(p->p_roles.nprim * sizeof(*(p->role_val_to_struct)),
+               kzalloc(p->p_roles.nprim * sizeof(*(p->role_val_to_struct)),
                        GFP_KERNEL);
        if (!p->role_val_to_struct)
                goto out;
 
        rc = -ENOMEM;
        p->user_val_to_struct =
-               kmalloc(p->p_users.nprim * sizeof(*(p->user_val_to_struct)),
+               kzalloc(p->p_users.nprim * sizeof(*(p->user_val_to_struct)),
                        GFP_KERNEL);
        if (!p->user_val_to_struct)
                goto out;
@@ -964,7 +964,7 @@ int policydb_context_isvalid(struct policydb *p, struct context *c)
                 * Role must be authorized for the type.
                 */
                role = p->role_val_to_struct[c->role - 1];
-               if (!ebitmap_get_bit(&role->types, c->type - 1))
+               if (!role || !ebitmap_get_bit(&role->types, c->type - 1))
                        /* role may not be associated with type */
                        return 0;