aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorStephen Smalley <sds@tycho.nsa.gov>2005-07-29 00:16:21 -0400
committerLinus Torvalds <torvalds@g5.osdl.org>2005-07-29 00:46:05 -0400
commit911656f8a630e36b22c7e2bba3317dec9174209c (patch)
tree2257dd4c04f4d234caf770a748b290b4d144fcf5
parentf0b9d796002d9d39575cf1beabfb625f68b507fa (diff)
[PATCH] selinux: Fix address length checks in connect hook
This patch fixes the address length checks in the selinux_socket_connect hook to be no more restrictive than the underlying ipv4 and ipv6 code; otherwise, this hook can reject valid connect calls. This patch is in response to a bug report where an application was calling connect on an INET6 socket with an address that didn't include the optional scope id and failing due to these checks. Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov> Signed-off-by: James Morris <jmorris@redhat.com> Signed-off-by: Andrew Morton <akpm@osdl.org> Signed-off-by: Linus Torvalds <torvalds@osdl.org>
-rw-r--r--security/selinux/hooks.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 10fd51c9056d..2253f388234f 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -3126,12 +3126,12 @@ static int selinux_socket_connect(struct socket *sock, struct sockaddr *address,
3126 3126
3127 if (sk->sk_family == PF_INET) { 3127 if (sk->sk_family == PF_INET) {
3128 addr4 = (struct sockaddr_in *)address; 3128 addr4 = (struct sockaddr_in *)address;
3129 if (addrlen != sizeof(struct sockaddr_in)) 3129 if (addrlen < sizeof(struct sockaddr_in))
3130 return -EINVAL; 3130 return -EINVAL;
3131 snum = ntohs(addr4->sin_port); 3131 snum = ntohs(addr4->sin_port);
3132 } else { 3132 } else {
3133 addr6 = (struct sockaddr_in6 *)address; 3133 addr6 = (struct sockaddr_in6 *)address;
3134 if (addrlen != sizeof(struct sockaddr_in6)) 3134 if (addrlen < SIN6_LEN_RFC2133)
3135 return -EINVAL; 3135 return -EINVAL;
3136 snum = ntohs(addr6->sin6_port); 3136 snum = ntohs(addr6->sin6_port);
3137 } 3137 }