Commit ebd39d17 authored by Silvio Gissi's avatar Silvio Gissi Committed by Xiang Yang
Browse files

keys: Fix overwrite of key expiration on instantiation

stable inclusion
from stable-v5.10.217
commit ad2011ea787928b2accb5134f1e423b11fe80a8a
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I9TM8D
CVE: CVE-2024-36031

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=ad2011ea787928b2accb5134f1e423b11fe80a8a



--------------------------------

commit 9da27fb65a14c18efd4473e2e82b76b53ba60252 upstream.

The expiry time of a key is unconditionally overwritten during
instantiation, defaulting to turn it permanent. This causes a problem
for DNS resolution as the expiration set by user-space is overwritten to
TIME64_MAX, disabling further DNS updates. Fix this by restoring the
condition that key_set_expiry is only called when the pre-parser sets a
specific expiry.

Fixes: 39299bdd2546 ("keys, dns: Allow key types (eg. DNS) to be reclaimed immediately on expiry")
Signed-off-by: default avatarSilvio Gissi <sifonsec@amazon.com>
cc: David Howells <dhowells@redhat.com>
cc: Hazem Mohamed Abuelfotoh <abuehaze@amazon.com>
cc: linux-afs@lists.infradead.org
cc: linux-cifs@vger.kernel.org
cc: keyrings@vger.kernel.org
cc: netdev@vger.kernel.org
cc: stable@vger.kernel.org
Reviewed-by: default avatarJarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: default avatarJarkko Sakkinen <jarkko@kernel.org>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarXiang Yang <xiangyang3@huawei.com>
parent 65017336
Loading
Loading
Loading
Loading
+2 −1
Original line number Diff line number Diff line
@@ -464,6 +464,7 @@ static int __key_instantiate_and_link(struct key *key,
			if (authkey)
				key_invalidate(authkey);

			if (prep->expiry != TIME64_MAX)
				key_set_expiry(key, prep->expiry);
		}
	}