[PATCH 1/2] ipe: fix use-after-free when auditing a newly loaded policy
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Wed Sep 23 03:19:35 UTC 2026
> new_policy() audits the policy after ipe_new_policyfs_node() publishes it
> and drops the new directory's inode lock. A concurrent delete can free
> the policy while ipe_audit_policy_load() is still using it.
>
> Audit the successful load under that lock.
>
> Fixes: f44554b5067b ("audit,ipe: add IPE auditing support")
> Cc: stable at vger.kernel.org
> Assisted-by: claude-opus-5.5
> Signed-off-by: Fan Wu <wufan at kernel.org>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923031349.1216431-1-wufan@kernel.org?part=1
More information about the Linux-security-module-archive
mailing list