Re: [PATCH] fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()
Al Viro <[email protected]>
| Newsgroups | gmane.linux.kernel.stable,gmane.linux.file-systems,gmane.linux.nfs,gmane.linux.kernel |
|---|---|
| Message-ID | <20260603181523.GW2636677@ZenIV> |
On Wed, Jun 03, 2026 at 07:38:06PM +0200, Jann Horn wrote: > Fix it by taking rcu_read_lock() around the mount::mnt_ns access, like > in __prepend_path(). > + /* > + * Containing namespace. > + * Normally protected by namespace_sem, but there are also lockless > + * readers (which must use RCU to guard against the namespace being > + * freed). > + */ > + struct mnt_namespace *mnt_ns; Umm... It's somewhat subtle - at the very least you need to explain why there will be an RCU delay between umount_tree() clearing that and having the sucker freed.