From: Paul Moore <paul@xxxxxxxxxxxxxx> Date: Mon, 25 Feb 2019 19:06:06 -0500 > There are two array out-of-bounds memory accesses, one in > cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both > errors are embarassingly simple, and the fixes are straightforward. > > As a FYI for anyone backporting this patch to kernels prior to v4.8, > you'll want to apply the netlbl_bitmap_walk() patch to > cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before > Linux v4.8. > > Reported-by: Jann Horn <jannh@xxxxxxxxxx> > Fixes: 446fda4f2682 ("[NetLabel]: CIPSOv4 engine") > Fixes: 3faa8f982f95 ("netlabel: Move bitmap manipulation functions to the NetLabel core.") > Signed-off-by: Paul Moore <paul@xxxxxxxxxxxxxx> Applied, thanks Paul.