mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
fhandle: reject detached mounts in capable_wrt_mount()
The recent fhandle RCU fix moved the mount namespace capability check
into capable_wrt_mount(), so a non-NULL mnt_namespace survives the
ns_capable() dereference. The helper still assumes the later
READ_ONCE(mount->mnt_ns) must be non-NULL because may_decode_fh()
checked is_mounted() first.
That assumption is not stable. A detached mount from
open_tree(..., OPEN_TREE_CLONE) can be dissolved on fput while
open_by_handle_at() is between those checks, and umount_tree() can
clear mount->mnt_ns. If the helper observes NULL, it dereferences
mnt_ns->user_ns and panics.
Return false when the RCU read observes a detached mount. This keeps
the relaxed permission path conservative: a mount no longer attached
to a namespace cannot authorize open_by_handle_at() access.
Fixes: 620c266f39 ("fhandle: relax open_by_handle_at() permission checks")
Cc: stable@vger.kernel.org
Signed-off-by: David Lee <david.lee@trailofbits.com>
Assisted-by: LLM
Link: https://patch.msgid.link/20260701114438.24431-1-david.lee@trailofbits.com
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
This commit is contained in:
parent
e0df90e4c6
commit
6c73247174
|
|
@ -295,7 +295,7 @@ static bool capable_wrt_mount(struct mount *mount)
|
|||
*/
|
||||
guard(rcu)();
|
||||
mnt_ns = READ_ONCE(mount->mnt_ns);
|
||||
return ns_capable(mnt_ns->user_ns, CAP_SYS_ADMIN);
|
||||
return mnt_ns && ns_capable(mnt_ns->user_ns, CAP_SYS_ADMIN);
|
||||
}
|
||||
|
||||
static inline int may_decode_fh(struct handle_to_path_ctx *ctx,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user