Files
linux-stable-mirror/kernel
Ricardo Robaina 1526f3c988 audit: fix potential integer overflow in audit_log_n_hex()
[ Upstream commit 65dfde57d1 ]

The function calculates new_len as len << 1 for hex encoding. This
has two overflow risks: the shift itself can overflow when len is
large, and the result can be truncated when assigned to new_len
(declared as int) from the size_t calculation.

Fix by using check_shl_overflow() to catch shift overflow and
changing new_len and loop counter i to size_t to prevent truncation.

Cc: stable@vger.kernel.org
Fixes: 168b717395 ("AUDIT: Clean up logging of untrusted strings")
Reviewed-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Ricardo Robaina <rrobaina@redhat.com>
[PM: remove vertical whitspace noise]
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-07-24 16:03:51 +02:00
..
2025-11-24 10:30:06 +01:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
2024-10-17 15:24:37 +02:00
…
…
…
…
…
…
2024-06-12 11:12:52 +02:00
…
2026-01-11 15:21:17 +01:00
…
…
…
…
…
…
…
…