-
Bug
-
Resolution: Done-Errata
-
Normal
-
rhel-10.0.beta
-
None
-
libsepol-3.7-4.el10
-
None
-
Low
-
2
-
rhel-security-selinux
-
ssg_security
-
26
-
3
-
False
-
False
-
-
No
-
SELINUX 241016 - 241106, SELINUX 241106 - 241127
-
Release Note Not Required
-
None
Error: OVERRUN (CWE-119):
libsepol-3.6/cil/src/cil_resolve_ast.c:3157: assignment: Assigning: "sym_index" = "CIL_SYM_UNKNOWN".
libsepol-3.6/cil/src/cil_resolve_ast.c:3189: overrun-call: Overrunning callee's array of size 19 by passing argument "sym_index" (which evaluates to 20) in call to "cil_resolve_name".
# 3187| switch (curr->flavor) {
# 3188| case CIL_STRING:
# 3189|-> rc = cil_resolve_name(parent, curr->data, sym_index, db, &res_datum);
# 3190| if (rc != SEPOL_OK) {
# 3191| goto exit;
- clones
-
RHEL-28966 cil_resolve_ast.c:3157: assignment: Assigning: "sym_index" = "CIL_SYM_UNKNOWN".
-
- Closed
-
- links to
-
RHBA-2024:140957
libsepol bug fix and enhancement update