On Jul 18, 2026 Zhan Xusheng <[email protected]> wrote:
> 
> audit_log_n_string() computes new_len as "slen + 3" (enclosing quotes
> plus the NUL terminator) and stores it into an int, while slen is a
> size_t.  For a sufficiently large slen the addition can overflow and/or
> the result be truncated when assigned to the int new_len, so the
> "new_len > avail" check can be bypassed and the subsequent
> memcpy(ptr, string, slen) can write past the skb tail.
> 
> This is the same class of bug that was fixed for the hex sibling in
> commit 65dfde57d1e2 ("audit: fix potential integer overflow in
> audit_log_n_hex()"); both helpers are reached through
> audit_log_n_untrustedstring() with the same length source.
> 
> Make new_len a size_t and use check_add_overflow() to catch the
> overflow, mirroring the audit_log_n_hex() fix.  No functional change for
> the in-tree callers, which all pass bounded lengths.
> 
> Fixes: 168b7173959f ("AUDIT: Clean up logging of untrusted strings")
> Cc: [email protected]
> Signed-off-by: Zhan Xusheng <[email protected]>
> ---
> v2:
>  - drop the unnecessary (size_t) cast on the constant (Paul Moore)
>  - emit "?" instead of "\"?\"" on overflow, matching
>    audit_log_n_hex() (Paul Moore)
> 
>  kernel/audit.c | 11 +++++++++--
>  1 file changed, 9 insertions(+), 2 deletions(-)

Merged into audit/stable-7.2 with the intent of sending this up to Linus
once it has gone through some testing.  Thanks!

--
paul-moore.com

Reply via email to