[PATCH 1/3] fscrypt: destroy keyring after security_sb_delete()

Christian Brauner brauner at kernel.org
Tue Mar 14 09:28:29 UTC 2023


On Mon, Mar 13, 2023 at 03:12:29PM -0700, Eric Biggers wrote:
> From: Eric Biggers <ebiggers at google.com>
> 
> fscrypt_destroy_keyring() must be called after all potentially-encrypted
> inodes were evicted; otherwise it cannot safely destroy the keyring.
> Since inodes that are in-use by the Landlock LSM don't get evicted until
> security_sb_delete(), this means that fscrypt_destroy_keyring() must be
> called *after* security_sb_delete().
> 
> This fixes a WARN_ON followed by a NULL dereference, only possible if
> Landlock was being used on encrypted files.
> 
> Fixes: d7e7b9af104c ("fscrypt: stop using keyrings subsystem for fscrypt_master_key")
> Cc: stable at vger.kernel.org
> Reported-by: syzbot+93e495f6a4f748827c88 at syzkaller.appspotmail.com
> Link: https://lore.kernel.org/r/00000000000044651705f6ca1e30@google.com
> Signed-off-by: Eric Biggers <ebiggers at google.com>
> ---

Looks good,
Reviewed-by: Christian Brauner <brauner at kernel.org>



More information about the Linux-security-module-archive mailing list