git: 5d0b87669a91 - main - mac_bsdextended: reject negative rule indices in sysctl_rule()
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 16 Sep 2026 15:35:09 UTC
The branch main has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=5d0b87669a91244e330a35fc973e6c60f92f6d1f
commit 5d0b87669a91244e330a35fc973e6c60f92f6d1f
Author: Andrew Griffiths <andrew@calif.io>
AuthorDate: 2026-09-16 13:04:46 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-16 15:34:31 +0000
mac_bsdextended: reject negative rule indices in sysctl_rule()
The security.mac.bsdextended.rules.<N> node handler takes N as
`index = name[0]` (a signed int) and only checks
`index >= MAC_BSDEXTENDED_MAXRULES`. A negative index is caught on
the read branch, but the write-only add and delete
branches proceed to `rules[index]` unconditionally.
Reject `index < 0` alongside the existing upper-bound check.
Submitted by calif.io for the OpenAI Patch The Planet program
Signed-off-by: Andrew Griffiths <andrew@calif.io>
Reviewed by: markj
MFC after: 2 weeks
---
sys/security/mac_bsdextended/mac_bsdextended.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/sys/security/mac_bsdextended/mac_bsdextended.c b/sys/security/mac_bsdextended/mac_bsdextended.c
index bf95c008e2f2..5047a723fe01 100644
--- a/sys/security/mac_bsdextended/mac_bsdextended.c
+++ b/sys/security/mac_bsdextended/mac_bsdextended.c
@@ -143,7 +143,7 @@ sysctl_rule(SYSCTL_HANDLER_ARGS)
if (namelen != 1)
return (EINVAL);
index = name[0];
- if (index >= MAC_BSDEXTENDED_MAXRULES)
+ if (index < 0 || index >= MAC_BSDEXTENDED_MAXRULES)
return (ENOENT);
ruleptr = NULL;
@@ -157,7 +157,7 @@ sysctl_rule(SYSCTL_HANDLER_ARGS)
mtx_lock(&ugidfw_mtx);
if (req->oldptr) {
- if (index < 0 || index > rule_slots + 1) {
+ if (index > rule_slots + 1) {
error = ENOENT;
goto out;
}