[PATCH] dm-verity: clear LSM integrity state on suspend

sashiko-bot at kernel.org sashiko-bot at kernel.org
Mon Sep 21 22:16:26 UTC 2026


Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] dm-verity: clearing LSM state on suspend breaks IPE for cached files
- [High] ipe: Use-After-Free in evaluate_dmv_roothash() due to missing RCU
--

commit 0a1a0f42158da1707e32f8b9739a8420e73985d1
Author: Fan Wu <wufan at kernel.org>

dm-verity: clear LSM integrity state on suspend

This commit updates dm-verity to clear the published root hash and signature
state from the LSM security blob during verity_postsuspend(). This prevents
the block device from retaining stale attributes if the verity target is
replaced with a different target type.

> diff --git a/drivers/md/dm-verity-target.c b/drivers/md/dm-verity-target.c
> index cb105ccc47ecb..6d589867623c0 100644
> --- a/drivers/md/dm-verity-target.c
> +++ b/drivers/md/dm-verity-target.c

[ ... ]

> @@ -1779,8 +1781,31 @@ static int verity_preresume(struct dm_target *ti)
>  	return r;
>  }
>  
> +static void verity_security_clear_integrity(struct dm_target *ti)
> +{
> +	struct block_device *bdev = dm_disk(dm_table_get_md(ti->table))->part0;
> +
> +	security_bdev_setintegrity(bdev, LSM_INT_DMVERITY_ROOTHASH, NULL, 0);

[Severity: High]
Does passing NULL to security_bdev_setintegrity() trigger a use-after-free
in IPE?

When this is called, ipe_bdev_setintegrity() appears to free the root hash
without RCU synchronization:

security/ipe/hooks.c:ipe_bdev_setintegrity() {
	if (!value) {
		ipe_digest_free(blob->root_hash);
		blob->root_hash = NULL;
...

If a concurrent thread is evaluating an mprotect or execve call, could it
dereference this freed memory in evaluate_dmv_roothash()?

security/ipe/eval.c:evaluate_dmv_roothash() {
	...
	ipe_digest_eval(p->value, ctx->ipe_bdev->root_hash);
...

> +	verity_security_clear_signature(bdev);
> +}
> +
> +#else
> +
> +static inline void verity_security_clear_integrity(struct dm_target *ti)
> +{
> +}
> +
>  #endif /* CONFIG_SECURITY */
>  
> +static void verity_postsuspend(struct dm_target *ti)
> +{
> +	struct dm_verity *v = ti->private;
> +
> +	flush_workqueue(v->verify_wq);
> +	dm_bufio_client_reset(v->bufio);
> +	verity_security_clear_integrity(ti);

[Severity: High]
Does unconditionally clearing the integrity state on every table suspend break
IPE evaluation for already cached files?

During a temporary freeze or table reload, clearing the LSM integrity state
will cause concurrent VFS operations on already-cached files to see a cleared
state. Will this result in spurious -EACCES failures since IPE will deny
access despite the files being valid?

> +}
> +
>  static struct target_type verity_target = {
>  	.name		= "verity",
>  /* Note: the LSMs depend on the singleton and immutable features */

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921220516.121589-1-wufan@kernel.org?part=1



More information about the Linux-security-module-archive mailing list