CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the SELinux implementation, specifically in the `selinux_sctp_bind_connect()` function, which improperly dereferences `sk->sk_socket` without ensuring it is non-NULL. This could lead to potential null pointer dereference issues when invoked from the ASCONF softirq path, potentially impacting system stability and security. Linux system administrators and developers utilizing SELinux should prioritize addressing this vulnerability to maintain system integrity and prevent exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() selinux_sctp_bind_connect() dereferences sk->sk_socket to pass a struct socket * to selinux_socket_bind() and selinux_socket_connect_helper(). However, when the hook is invoked from the ASCONF softirq path (sctp_process_asconf), there is no file reference guaranteeing that sk->sk_socket is non-NULL. The setsockopt callers (bindx, connectx, set_primary, sendmsg connect) hold a file reference and are not affected. Both selinux_socket_bind() and selinux_socket_connect_helper() immediately resolve sock->sk, never using the struct socket * for anything else. Refactor the inner logic into helpers that take a struct sock * directly so that selinux_sctp_bind_connect() never needs to touch sk->sk_socket at all.