lkml.org 
[lkml]   [2026]   [Jun]   [3]   [last100]   RSS Feed
Views: [wrap][no wrap]   [headers]  [forward] 
 
Messages in this thread
/
Date
From
SubjectRe: [PATCH] fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
On Wed, Jun 03, 2026 at 07:38:06PM +0200, Jann Horn wrote:

> Fix it by taking rcu_read_lock() around the mount::mnt_ns access, like
> in __prepend_path().

> + /*
> + * Containing namespace.
> + * Normally protected by namespace_sem, but there are also lockless
> + * readers (which must use RCU to guard against the namespace being
> + * freed).
> + */
> + struct mnt_namespace *mnt_ns;

Umm... It's somewhat subtle - at the very least you need to explain why
there will be an RCU delay between umount_tree() clearing that and
having the sucker freed.

\
 
 \ /
  Last update: 2026-06-03 20:22    [W:0.083 / U:0.180 seconds]
©2003-2020 Jasper Spaans|hosted at Digital Ocean and my Meterkast|Read the blog