• Paul Moore's avatar
    audit: check the length of userspace generated audit records · 763dafc5
    Paul Moore authored
    Commit 75612528 ("audit: always check the netlink payload length
    in audit_receive_msg()") fixed a number of missing message length
    checks, but forgot to check the length of userspace generated audit
    records.  The good news is that you need CAP_AUDIT_WRITE to submit
    userspace audit records, which is generally only given to trusted
    processes, so the impact should be limited.
    
    Cc: stable@vger.kernel.org
    Fixes: 75612528 ("audit: always check the netlink payload length in audit_receive_msg()")
    Reported-by: syzbot+49e69b4d71a420ceda3e@syzkaller.appspotmail.com
    Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
    763dafc5
audit.c 61.6 KB