[apparmor] [PATCH] APPARMOR: Fix NULL Pointer dereference while __add_new_profile
wzt.wzt at gmail.com
wzt.wzt at gmail.com
Fri Nov 26 15:18:47 GMT 2010
In aa_replace_profiles(), if __lookup_parent() path failed, policy is set
to NULL and goto audit label, old_profile and rename_profile are both NULL,
__add_new_profile is called, the parameter policy is NULL, it will cause
NULL pointer dereference via __list_add_profile(&policy->profiles, profile);
Signed-off-by: Zhitong Wang <zhitong.wangzt at alibaba-inc.com>
---
security/apparmor/policy.c | 2 ++
1 files changed, 2 insertions(+), 0 deletions(-)
diff --git a/security/apparmor/policy.c b/security/apparmor/policy.c
index 52cc865..832d9e9 100644
--- a/security/apparmor/policy.c
+++ b/security/apparmor/policy.c
@@ -940,6 +940,8 @@ static int replacement_allowed(struct aa_profile *profile, int noreplace,
static void __add_new_profile(struct aa_namespace *ns, struct aa_policy *policy,
struct aa_profile *profile)
{
+ if (!policy)
+ return ;
if (policy != &ns->base)
/* released on profile replacement or free_profile */
profile->parent = aa_get_profile((struct aa_profile *) policy);
--
1.6.5.3
More information about the AppArmor
mailing list