[PATCH] dm-verity: clear LSM integrity state on suspend
Fan Wu
wufan at kernel.org
Mon Sep 21 23:55:14 UTC 2026
On Mon, Sep 21, 2026 at 3:18 PM <sashiko-bot at kernel.org> wrote:
>
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
> - [High] dm-verity: clearing LSM state on suspend breaks IPE for cached files
> - [High] ipe: Use-After-Free in evaluate_dmv_roothash() due to missing RCU
> --
>
> commit 0a1a0f42158da1707e32f8b9739a8420e73985d1
> Author: Fan Wu <wufan at kernel.org>
>
> dm-verity: clear LSM integrity state on suspend
>
> This commit updates dm-verity to clear the published root hash and signature
> state from the LSM security blob during verity_postsuspend(). This prevents
> the block device from retaining stale attributes if the verity target is
> replaced with a different target type.
>
> > diff --git a/drivers/md/dm-verity-target.c b/drivers/md/dm-verity-target.c
> > index cb105ccc47ecb..6d589867623c0 100644
> > --- a/drivers/md/dm-verity-target.c
> > +++ b/drivers/md/dm-verity-target.c
>
> [ ... ]
>
> > @@ -1779,8 +1781,31 @@ static int verity_preresume(struct dm_target *ti)
> > return r;
> > }
> >
> > +static void verity_security_clear_integrity(struct dm_target *ti)
> > +{
> > + struct block_device *bdev = dm_disk(dm_table_get_md(ti->table))->part0;
> > +
> > + security_bdev_setintegrity(bdev, LSM_INT_DMVERITY_ROOTHASH, NULL, 0);
>
> [Severity: High]
> Does passing NULL to security_bdev_setintegrity() trigger a use-after-free
> in IPE?
>
> When this is called, ipe_bdev_setintegrity() appears to free the root hash
> without RCU synchronization:
>
> security/ipe/hooks.c:ipe_bdev_setintegrity() {
> if (!value) {
> ipe_digest_free(blob->root_hash);
> blob->root_hash = NULL;
> ...
>
> If a concurrent thread is evaluating an mprotect or execve call, could it
> dereference this freed memory in evaluate_dmv_roothash()?
>
> security/ipe/eval.c:evaluate_dmv_roothash() {
> ...
> ipe_digest_eval(p->value, ctx->ipe_bdev->root_hash);
> ...
>
I will post an UAF fix for this, however this is an ipe issue so not
blocking this patch.
> > + verity_security_clear_signature(bdev);
> > +}
> > +
> > +#else
> > +
> > +static inline void verity_security_clear_integrity(struct dm_target *ti)
> > +{
> > +}
> > +
> > #endif /* CONFIG_SECURITY */
> >
> > +static void verity_postsuspend(struct dm_target *ti)
> > +{
> > + struct dm_verity *v = ti->private;
> > +
> > + flush_workqueue(v->verify_wq);
> > + dm_bufio_client_reset(v->bufio);
> > + verity_security_clear_integrity(ti);
>
> [Severity: High]
> Does unconditionally clearing the integrity state on every table suspend break
> IPE evaluation for already cached files?
>
> During a temporary freeze or table reload, clearing the LSM integrity state
> will cause concurrent VFS operations on already-cached files to see a cleared
> state. Will this result in spurious -EACCES failures since IPE will deny
> access despite the files being valid?
>
This is the expected behavior. Tracking the verification status of
cached data is impractical.
The deny issue can also be avoided by creating a new dm device instead
of swapping tables.
-Fan
More information about the Linux-security-module-archive
mailing list