summaryrefslogtreecommitdiff
path: root/security
diff options
context:
space:
mode:
authorMikhail Ivanov <ivanov.mikhail1@huawei-partners.com>2024-11-12 22:52:03 +0800
committerPaul Moore <paul@paul-moore.com>2024-12-11 14:57:47 -0500
commit034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd (patch)
tree9a443dec1607ebe064a83bd3335b8efe13a34995 /security
parentc75c7945cd49c05404b00358108084a175a5fb29 (diff)
downloadlinux-034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd.tar.gz
linux-034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd.tar.bz2
linux-034294fbfdf0ded4f931f9503d2ca5bbf8b9aebd.zip
selinux: Fix SCTP error inconsistency in selinux_socket_bind()
Check sk->sk_protocol instead of security class to recognize SCTP socket. SCTP socket is initialized with SECCLASS_SOCKET class if policy does not support EXTSOCKCLASS capability. In this case bind(2) hook wrongfully return EAFNOSUPPORT instead of EINVAL. The inconsistency was detected with help of Landlock tests: https://lore.kernel.org/all/b58680ca-81b2-7222-7287-0ac7f4227c3c@huawei-partners.com/ Fixes: 0f8db8cc73df ("selinux: add AF_UNSPEC and INADDR_ANY checks to selinux_socket_bind()") Signed-off-by: Mikhail Ivanov <ivanov.mikhail1@huawei-partners.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security')
-rw-r--r--security/selinux/hooks.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 2afc45f355a4..5e5f3398f39d 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -4835,7 +4835,7 @@ out:
return err;
err_af:
/* Note that SCTP services expect -EINVAL, others -EAFNOSUPPORT. */
- if (sksec->sclass == SECCLASS_SCTP_SOCKET)
+ if (sk->sk_protocol == IPPROTO_SCTP)
return -EINVAL;
return -EAFNOSUPPORT;
}