diff options
| author | Mikhail Ivanov <[email protected]> | 2024-11-12 14:52:03 +0000 |
|---|---|---|
| committer | Paul Moore <[email protected]> | 2024-12-11 19:57:47 +0000 |
| commit | 034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd (patch) | |
| tree | 9a443dec1607ebe064a83bd3335b8efe13a34995 /security/selinux/hooks.c | |
| parent | selinux: use native iterator types (diff) | |
| download | kernel-034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd.tar.gz kernel-034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd.zip | |
selinux: Fix SCTP error inconsistency in selinux_socket_bind()
Check sk->sk_protocol instead of security class to recognize SCTP socket.
SCTP socket is initialized with SECCLASS_SOCKET class if policy does not
support EXTSOCKCLASS capability. In this case bind(2) hook wrongfully
return EAFNOSUPPORT instead of EINVAL.
The inconsistency was detected with help of Landlock tests:
https://lore.kernel.org/all/[email protected]/
Fixes: 0f8db8cc73df ("selinux: add AF_UNSPEC and INADDR_ANY checks to selinux_socket_bind()")
Signed-off-by: Mikhail Ivanov <[email protected]>
Signed-off-by: Paul Moore <[email protected]>
Diffstat (limited to 'security/selinux/hooks.c')
| -rw-r--r-- | security/selinux/hooks.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index 2afc45f355a4..5e5f3398f39d 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -4835,7 +4835,7 @@ out: return err; err_af: /* Note that SCTP services expect -EINVAL, others -EAFNOSUPPORT. */ - if (sksec->sclass == SECCLASS_SCTP_SOCKET) + if (sk->sk_protocol == IPPROTO_SCTP) return -EINVAL; return -EAFNOSUPPORT; } |
