Re: [PATCH] eventfs: Fix use-after-free in eventfs_remove_rec()

Masami Hiramatsu (Google) <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.linux-trace-kernel
Message-ID <[email protected]>
On Wed,  5 Aug 2026 22:27:19 -0400
Shuangpeng Bai <[email protected]> wrote:

> eventfs_remove_rec() recursively removes the child at the current loop
> position. After the recursive call returns, list_for_each_entry() advances
> by reading list.next from the removed child.
> 
> If free_ei() drops the final reference, release_ei() reuses the list/rcu
> union to queue an SRCU callback. The child may be freed before that read.
> The eventfs_mutex serializes list updates, but it does not keep the removed
> child alive or prevent the SRCU callback from running.
> 
> Use list_for_each_entry_safe() to save the next sibling before recursively
> removing the current child.
> 

Looks good to me.

Acked-by: Masami Hiramatsu (Google) <[email protected]>

Thanks,

> Fixes: 43aa6f97c2d0 ("eventfs: Get rid of dentry pointers without refcounts")
> Cc: [email protected]
> Signed-off-by: Shuangpeng Bai <[email protected]>
> ---
>  fs/tracefs/event_inode.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/fs/tracefs/event_inode.c b/fs/tracefs/event_inode.c
> index 39c7a34531e8..93bc4f83b73e 100644
> --- a/fs/tracefs/event_inode.c
> +++ b/fs/tracefs/event_inode.c
> @@ -822,7 +822,7 @@ struct eventfs_inode *eventfs_create_events_dir(const char *name, struct dentry
>   */
>  static void eventfs_remove_rec(struct eventfs_inode *ei, int level)
>  {
> -	struct eventfs_inode *ei_child;
> +	struct eventfs_inode *ei_child, *tmp;
>  
>  	/*
>  	 * Check recursion depth. It should never be greater than 3:
> @@ -835,7 +835,7 @@ static void eventfs_remove_rec(struct eventfs_inode *ei, int level)
>  		return;
>  
>  	/* search for nested folders or files */
> -	list_for_each_entry(ei_child, &ei->children, list)
> +	list_for_each_entry_safe(ei_child, tmp, &ei->children, list)
>  		eventfs_remove_rec(ei_child, level + 1);
>  
>  	list_del_rcu(&ei->list);
> -- 
> 2.43.0
> 


-- 
Masami Hiramatsu (Google) <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.