Message ID | 20230512093001.49208-3-cgzones@googlemail.com (mailing list archive) |
---|---|
State | Accepted |
Commit | ac015a3996e8 |
Delegated to: | Petr Lautrbach |
Headers | show |
Series | [1/5] libsepol: validate some object contexts | expand |
diff --git a/libsepol/src/policydb_validate.c b/libsepol/src/policydb_validate.c index e0d290ff..b34f83ec 100644 --- a/libsepol/src/policydb_validate.c +++ b/libsepol/src/policydb_validate.c @@ -545,6 +545,8 @@ static int validate_mls_semantic_cat(const mls_semantic_cat_t *cat, const valida goto bad; if (validate_value(cat->high, cats)) goto bad; + if (cat->low > cat->high) + goto bad; } return 0;
Signed-off-by: Christian Göttsche <cgzones@googlemail.com> --- libsepol/src/policydb_validate.c | 2 ++ 1 file changed, 2 insertions(+)