ipe: fix use-after-free when auditing a newly loaded policy

new_policy() audits the policy after ipe_new_policyfs_node() publishes it
and drops the new directory's inode lock. A concurrent delete can free
the policy while ipe_audit_policy_load() is still using it.

Audit the successful load under that lock.

Fixes: f44554b506 ("audit,ipe: add IPE auditing support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
[FW: remove model name according to latest guideline]
Signed-off-by: Fan Wu <wufan@kernel.org>
This commit is contained in:
Fan Wu 2026-09-22 20:13:48 -07:00
parent 93f51579e7
commit 9814077275
2 changed files with 6 additions and 5 deletions

View File

@ -159,18 +159,16 @@ static ssize_t new_policy(struct file *f, const char __user *data,
}
rc = ipe_new_policyfs_node(p);
if (rc)
goto out;
out:
kfree(copy);
if (rc < 0) {
ipe_free_policy(p);
ipe_audit_policy_load(ERR_PTR(rc));
} else {
ipe_audit_policy_load(p);
return rc;
}
return (rc < 0) ? rc : len;
return len;
}
static const struct file_operations np_fops = {

View File

@ -481,6 +481,9 @@ int ipe_new_policyfs_node(struct ipe_policy *p)
inode_lock(root);
p->policyfs = policyfs;
root->i_private = p;
/* Only audit signed policies from userspace */
if (p->pkcs7)
ipe_audit_policy_load(p);
inode_unlock(root);
return 0;