On Wed, 6 Dec 2017, Paul Moore wrote:

> From: Paul Moore <[email protected]>
> 
> We can't do anything reasonable in security_bounded_transition() if we
> don't have a policy loaded, and in fact we could run into problems
> with some of the code inside expecting a policy.  Fix these problems
> like we do many others in security/selinux/ss/services.c by checking
> to see if the policy is loaded (ss_initialized) and returning quickly
> if it isn't.
> 
> Reported-by: syzbot <[email protected]>
> Signed-off-by: Paul Moore <[email protected]>
> Acked-by: Stephen Smalley <[email protected]>


Reviewed-by: James Morris <[email protected]>


-- 
James Morris
<[email protected]>


Reply via email to