Thread (3 messages) 3 messages, 2 authors, 24d ago

Re: [PATCH] keys: Fix key_user use-after-free during ownership changes

From: Chengfeng Ye <hidden>
Date: 2026-09-03 18:04:16
Also in: keyrings, lkml

On Fri, Aug 28, 2026 at 6:06 AM Jarkko Sakkinen [off-list ref] wrote:
I hope you don't mind that I sanity check a bit:

 git grep "user->uid" security/keys
security/keys/internal.h:       uid = key->user->uid;
security/keys/key.c:            if (uid_lt(uid, user->uid))
security/keys/key.c:            else if (uid_gt(uid, user->uid))
security/keys/key.c:            unsigned maxbytes = uid_eq(key->user->uid, GLOBAL_ROOT_UID) ?
security/keys/proc.c:           if (kuid_has_mapping(user_ns, user->uid))
security/keys/proc.c:   unsigned maxkeys = uid_eq(user->uid, GLOBAL_ROOT_UID) ?
security/keys/proc.c:   unsigned maxbytes = uid_eq(user->uid, GLOBAL_ROOT_UID) ?
security/keys/proc.c:              from_kuid_munged(seq_user_ns(m), user->uid),
security/keys/process_keys.c:   uid_t uid = from_kuid(user_ns, cred->user->uid);
security/keys/process_keys.c:           uid_keyring = keyring_alloc(buf, cred->user->uid, INVALID_GID,
security/keys/process_keys.c:           session_keyring = keyring_alloc(buf, cred->user->uid, INVALID_GID,
security/keys/process_keys.c:                                               cred->user->uid));

Have you audited these and reflected against your current patch?

BR, Jarkko
Right, there are more sites that take and dereference key->user but
not serialized to prevent the UAF. I am going to send a v2 to protect
other sites affected by the data race.

Best regards,
Chengfeng
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help