diff options
| author | Zygmunt Krynicki <me@zygoon.pl> | 2026-05-02 13:37:14 +0200 |
|---|---|---|
| committer | John Johansen <john.johansen@canonical.com> | 2026-06-13 20:18:30 -0700 |
| commit | fea23bf73f0cae8ccb1d0684e4a3003874771f41 (patch) | |
| tree | dce15b41cdb45e16f82cb628b18d6dfb0aede64d /security/apparmor | |
| parent | e27bfb2ae9ad8522aea82d435fd6d73cccee7e17 (diff) | |
| download | lwn-fea23bf73f0cae8ccb1d0684e4a3003874771f41.tar.gz lwn-fea23bf73f0cae8ccb1d0684e4a3003874771f41.zip | |
apparmor: aa_getprocattr free procattr leak on format failure
aa_getprocattr() allocates the output string before rendering the label
into it. If the second aa_label_snxprint() call fails, the function
returned without freeing that allocation.
Free and clear the output pointer on the uncommon formatting failure path
before dropping the namespace reference.
Fixes: 76a1d263aba3 ("apparmor: switch getprocattr to using label_print fns()")
Reviewed-by: Tyler Hicks <code@thicks.com>
Reviewed-by: Ryan Lee <ryan.lee@canonical.com>
Signed-off-by: Zygmunt Krynicki <me@zygoon.pl>
Signed-off-by: John Johansen <john.johansen@canonical.com>
Diffstat (limited to 'security/apparmor')
| -rw-r--r-- | security/apparmor/procattr.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/security/apparmor/procattr.c b/security/apparmor/procattr.c index ce40f15d4952..c07b6e8fd9c9 100644 --- a/security/apparmor/procattr.c +++ b/security/apparmor/procattr.c @@ -54,6 +54,8 @@ int aa_getprocattr(struct aa_label *label, char **string, bool newline) FLAG_SHOW_MODE | FLAG_VIEW_SUBNS | FLAG_HIDDEN_UNCONFINED); if (len < 0) { + kfree(*string); + *string = NULL; aa_put_ns(current_ns); return len; } |
