On Jul 18, 2026 Zhan Xusheng <[email protected]> wrote: > > audit_log_n_string() computes new_len as "slen + 3" (enclosing quotes > plus the NUL terminator) and stores it into an int, while slen is a > size_t. For a sufficiently large slen the addition can overflow and/or > the result be truncated when assigned to the int new_len, so the > "new_len > avail" check can be bypassed and the subsequent > memcpy(ptr, string, slen) can write past the skb tail. > > This is the same class of bug that was fixed for the hex sibling in > commit 65dfde57d1e2 ("audit: fix potential integer overflow in > audit_log_n_hex()"); both helpers are reached through > audit_log_n_untrustedstring() with the same length source. > > Make new_len a size_t and use check_add_overflow() to catch the > overflow, mirroring the audit_log_n_hex() fix. No functional change for > the in-tree callers, which all pass bounded lengths. > > Fixes: 168b7173959f ("AUDIT: Clean up logging of untrusted strings") > Cc: [email protected] > Signed-off-by: Zhan Xusheng <[email protected]> > --- > v2: > - drop the unnecessary (size_t) cast on the constant (Paul Moore) > - emit "?" instead of "\"?\"" on overflow, matching > audit_log_n_hex() (Paul Moore) > > kernel/audit.c | 11 +++++++++-- > 1 file changed, 9 insertions(+), 2 deletions(-)
Merged into audit/stable-7.2 with the intent of sending this up to Linus once it has gone through some testing. Thanks! -- paul-moore.com

