| The vulnerability CVE-2021-46971 is a bug in the Linux kernel's perf/core subsystem. The issue arises from an unconditional call to the `security_locked_down()` function, which is used to check the lockdown state of the system. This call is made even when the result of the lockdown state query is not actually used, specifically when the `PERF_SAMPLE_REGS_INTR` bit is not set in the `attr.sample_type`. |
| |
| The problem with this unconditional call is that it can cause issues with certain Linux Security Modules (LSMs), such as SELinux. In SELinux, the lockdown hook implementation checks whether the current task has a "lockdown" class permission allowed in the policy. If the lockdown state query is made when the access control decision would be ignored, it generates a bogus permission check and audit record. |
| |
| The fix for this issue involves checking the `sample_type` first and only calling the `security_locked_down()` function when its result would actually be honored. This ensures that the lockdown state query is only made when necessary, preventing the issues with LSMs like SELinux. |
| |