Re: [PATCH] KEYS: add missing permission check for request_key() destination

From: David Howells
Date: Tue Nov 28 2017 - 05:13:10 EST


Eric Biggers <ebiggers3@xxxxxxxxx> wrote:

> + if (do_perm_check) {
> + ret = key_permission(make_key_ref(dest_keyring, 1),
> + KEY_NEED_WRITE);

dest_keyring may be NULL at this point as alloc_uid() doesn't automatically
create keyrings.

David