[GIT PULL] IPE fixes for 7.3-rc5
Fan Wu
wufan at kernel.org
Fri Sep 25 21:54:43 UTC 2026
Hi Linus,
Please merge this PR for the IPE fixes for 7.3.
This PR contains two commits that fix use-after-free issues found by
recent LLM-assisted code analysis.
The first commit moves successful policy load auditing under the new
policy directory's inode lock, preventing a concurrent policy deletion
from freeing the policy while it is still being audited.
The second commit protects the dm-verity root hash with RCU, preventing
policy evaluation from racing with root hash replacement during
preresume.
Both commits have been tested in linux-next since Tuesday without any
issues.
Thanks,
Fan
--
The following changes since commit 93f51579e7df248780214094418f205253383cc5:
Linux 7.3-rc4 (2026-09-20 13:48:15 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipe.git
tags/ipe-pr-20260925
for you to fetch changes up to 2776e9c28513a1c855a94792b292cbcc533418c8:
ipe: protect the dm-verity root hash with RCU (2026-09-25 13:30:27 -0700)
----------------------------------------------------------------
ipe/stable-7.3 PR 20260925
----------------------------------------------------------------
Fan Wu (2):
ipe: fix use-after-free when auditing a newly loaded policy
ipe: protect the dm-verity root hash with RCU
security/ipe/eval.c | 12 ++++++++----
security/ipe/eval.h | 2 +-
security/ipe/fs.c | 8 +++-----
security/ipe/hooks.c | 22 +++++++++++++++++-----
security/ipe/policy_fs.c | 3 +++
5 files changed, 32 insertions(+), 15 deletions(-)
More information about the Linux-security-module-archive
mailing list