[PATCH v3 1/2] keys: Protect key_user lifetime during ownership changes

sashiko-bot at kernel.org sashiko-bot at kernel.org
Sun Sep 27 16:36:10 UTC 2026


> keyctl_chown_key() replaces key->user under key->sem and drops the
> reference to the previous owner after releasing the semaphore. Readers
> which do not hold that semaphore can still be using the previous owner
> when key_user_put() frees it.
> 
> For example, namespace filtering in /proc/keys can race with chown:
> 
>   /proc/keys reader                 keyctl_chown_key()
>   user = key->user
>                                     key->user = newowner
>                                     key_user_put(old)
>                                       kfree(old)
>   read user->uid
> 
> An earlier instrumented run reported:
> [ ... ]
> outside the new critical sections for the separate accounting fix.
> 
> Fixes: 5801649d8b83 ("[PATCH] keys: let keyctl_chown() change a key's owner")
> Cc: stable at vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260927162528.943886-1-nicoyip.dev@gmail.com?part=1




More information about the Linux-security-module-archive mailing list