[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20220518092137.141626-1-gongruiqi1@huawei.com>
Date: Wed, 18 May 2022 09:21:37 +0000
From: "GONG, Ruiqi" <gongruiqi1@...wei.com>
To: Paul Moore <paul@...l-moore.com>,
Stephen Smalley <stephen.smalley.work@...il.com>,
Eric Paris <eparis@...isplace.org>,
"Kees Cook" <keescook@...omium.org>
CC: <selinux@...r.kernel.org>, <linux-kernel@...r.kernel.org>,
Wang Weiyang <wangweiyang2@...wei.com>,
Xiu Jianfeng <xiujianfeng@...wei.com>, <gongruiqi1@...wei.com>
Subject: [PATCH] selinux: add __randomize_layout to selinux_audit_data
Randomize the layout of struct selinux_audit_data as suggested in [1],
since it contains a pointer to struct selinux_state, an already
randomized strucure.
[1]: https://github.com/KSPP/linux/issues/188
Signed-off-by: GONG, Ruiqi <gongruiqi1@...wei.com>
---
security/selinux/include/avc.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/selinux/include/avc.h b/security/selinux/include/avc.h
index 2b372f98f2d7..5525b94fd266 100644
--- a/security/selinux/include/avc.h
+++ b/security/selinux/include/avc.h
@@ -53,7 +53,7 @@ struct selinux_audit_data {
u32 denied;
int result;
struct selinux_state *state;
-};
+} __randomize_layout;
/*
* AVC operations
--
2.17.1
Powered by blists - more mailing lists