OSS-Fuzz found a heap use-after-free when the CIL compiler destroys its database after failing to compile the following policy: (validatetrans x (eq t3 (a))) This is caused by the fact that the validatetrans AST object references a stack variable local to __cil_fill_constraint_leaf_expr, when parsing the list "(a)": struct cil_list *sub_list; cil_fill_list(current->next->next->cl_head, leaf_expr_flavor, &sub_list); cil_list_append(*leaf_expr, CIL_LIST, &sub_list); Drop the & sign to really add the list like it is supposed to be. Fixes: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28507 Signed-off-by: Nicolas Iooss <nicolas.iooss@xxxxxxx> --- libsepol/cil/src/cil_build_ast.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libsepol/cil/src/cil_build_ast.c b/libsepol/cil/src/cil_build_ast.c index 0c9015cef578..4caff3cb3c98 100644 --- a/libsepol/cil/src/cil_build_ast.c +++ b/libsepol/cil/src/cil_build_ast.c @@ -2714,7 +2714,7 @@ static int __cil_fill_constraint_leaf_expr(struct cil_tree_node *current, enum c } else if (r_flavor == CIL_LIST) { struct cil_list *sub_list; cil_fill_list(current->next->next->cl_head, leaf_expr_flavor, &sub_list); - cil_list_append(*leaf_expr, CIL_LIST, &sub_list); + cil_list_append(*leaf_expr, CIL_LIST, sub_list); } else { cil_list_append(*leaf_expr, CIL_CONS_OPERAND, (void *)r_flavor); } -- 2.29.2