mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
keys: make keyring key-chunk byte order agree with keyring_diff_objects()
[ Upstream commit58565eef0f] keyring_get_key_chunk() loads description bytes into the index chunk low address first, while keyring_diff_objects() numbers the first differing bit from the low end and folds the absolute byte index into the level without removing the inline-prefix offset the level already carries. The two disagree on byte order and bit position, so the array can be told two keys first differ at a bit that does not differ in the chunk the walker uses, letting crafted descriptions collide into one node. Load the chunk in the order keyring_diff_objects() assumes and drop the inline-prefix length when folding the byte index into the level. This only changes the in-memory ordering used to place keys within a keyring; add, search and read of non-colliding keys are unaffected. Fixes:f771fde820("keys: Simplify key description management") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Tested-by: Jarkko Sakkinen <jarkko@kernel.org> Link: https://lore.kernel.org/r/20260719161505.2423935-3-michael.bommarito@gmail.com Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
d1933e03e8
commit
bd0f976ef8
@@ -293,9 +293,10 @@ static unsigned long keyring_get_key_chunk(const void *data, int level)
|
||||
desc_len -= offset;
|
||||
if (desc_len > n)
|
||||
desc_len = n;
|
||||
d += desc_len;
|
||||
do {
|
||||
chunk <<= 8;
|
||||
chunk |= *d++;
|
||||
chunk |= *--d;
|
||||
} while (--desc_len > 0);
|
||||
return chunk;
|
||||
}
|
||||
@@ -376,7 +377,7 @@ same:
|
||||
return -1;
|
||||
|
||||
differ_plus_i:
|
||||
level += i;
|
||||
level += i - (int)sizeof(a->desc);
|
||||
differ:
|
||||
i = level * 8 + __ffs(seg_a ^ seg_b);
|
||||
return i;
|
||||
|
||||
Reference in New Issue
Block a user