mirror of
https://github.com/torvalds/linux.git
synced 2026-09-28 12:02:03 +02:00
ipe: fix use-after-free when auditing a newly loaded policy
new_policy() audits the policy after ipe_new_policyfs_node() publishes it
and drops the new directory's inode lock. A concurrent delete can free
the policy while ipe_audit_policy_load() is still using it.
Audit the successful load under that lock.
Fixes: f44554b506 ("audit,ipe: add IPE auditing support")
Cc: stable@vger.kernel.org
Assisted-by: LLM
[FW: remove model name according to latest guideline]
Signed-off-by: Fan Wu <wufan@kernel.org>
This commit is contained in:
parent
93f51579e7
commit
9814077275
|
|
@ -159,18 +159,16 @@ static ssize_t new_policy(struct file *f, const char __user *data,
|
|||
}
|
||||
|
||||
rc = ipe_new_policyfs_node(p);
|
||||
if (rc)
|
||||
goto out;
|
||||
|
||||
out:
|
||||
kfree(copy);
|
||||
if (rc < 0) {
|
||||
ipe_free_policy(p);
|
||||
ipe_audit_policy_load(ERR_PTR(rc));
|
||||
} else {
|
||||
ipe_audit_policy_load(p);
|
||||
return rc;
|
||||
}
|
||||
return (rc < 0) ? rc : len;
|
||||
|
||||
return len;
|
||||
}
|
||||
|
||||
static const struct file_operations np_fops = {
|
||||
|
|
|
|||
|
|
@ -481,6 +481,9 @@ int ipe_new_policyfs_node(struct ipe_policy *p)
|
|||
inode_lock(root);
|
||||
p->policyfs = policyfs;
|
||||
root->i_private = p;
|
||||
/* Only audit signed policies from userspace */
|
||||
if (p->pkcs7)
|
||||
ipe_audit_policy_load(p);
|
||||
inode_unlock(root);
|
||||
|
||||
return 0;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user