sst-linux/security/selinux
Thiébaud Weksteen c79324d42f selinux: ignore unknown extended permissions
commit 900f83cf376bdaf798b6f5dcb2eae0c822e908b6 upstream.

When evaluating extended permissions, ignore unknown permissions instead
of calling BUG(). This commit ensures that future permissions can be
added without interfering with older kernels.

Cc: stable@vger.kernel.org
Fixes: fa1aa143ac ("selinux: extended permissions for ioctls")
Signed-off-by: Thiébaud Weksteen <tweek@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Acked-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-01-09 13:29:56 +01:00
..
include ima: Avoid blocking in RCU read-side critical section 2024-07-11 12:47:16 +02:00
ss selinux: ignore unknown extended permissions 2025-01-09 13:29:56 +01:00
.gitignore
avc.c selinux: fix potential counting error in avc_add_xperms_decision() 2024-08-29 17:30:15 +02:00
hooks.c selinux,smack: don't bypass permissions check in inode_setsecctx hook 2024-10-17 15:21:15 +02:00
ibpkey.c
ima.c
Kconfig
Makefile
netif.c
netlabel.c
netlink.c
netnode.c
netport.c
nlmsgtab.c
selinuxfs.c selinux: improve error checking in sel_write_load() 2024-11-01 01:56:07 +01:00
status.c
xfrm.c