[PATCH v3 1/2] keys: Protect key_user lifetime during ownership changes
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Sun Sep 27 16:36:10 UTC 2026
> keyctl_chown_key() replaces key->user under key->sem and drops the
> reference to the previous owner after releasing the semaphore. Readers
> which do not hold that semaphore can still be using the previous owner
> when key_user_put() frees it.
>
> For example, namespace filtering in /proc/keys can race with chown:
>
> /proc/keys reader keyctl_chown_key()
> user = key->user
> key->user = newowner
> key_user_put(old)
> kfree(old)
> read user->uid
>
> An earlier instrumented run reported:
> [ ... ]
> outside the new critical sections for the separate accounting fix.
>
> Fixes: 5801649d8b83 ("[PATCH] keys: let keyctl_chown() change a key's owner")
> Cc: stable at vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260927162528.943886-1-nicoyip.dev@gmail.com?part=1
More information about the Linux-security-module-archive
mailing list