Re: [PATCH] fsverity: RCU-delay the freeing of struct fsverity_info
From: Eric Biggers
Date: Fri Oct 02 2026 - 17:47:13 EST
On Thu, Oct 01, 2026 at 10:13:49AM -0700, Eric Biggers wrote:
> __fsverity_get_info() calls rhashtable_lookup_fast(), which just uses
> rcu_read_lock() and doesn't directly synchronize with
> fsverity_remove_info().
>
> For the same inode this isn't a problem: its fsverity_info is removed
> only at inode eviction time or upon failure to enable verity, when the
> inode no longer needs its fsverity_info and it will no longer be
> accessed via that inode.
>
> However, this is broken and can cause a use-after-free for concurrent
> __fsverity_get_info() for *different* inodes. Those rely on following
> fsverity_info::rhash_head in the rhashtable under rcu_read_lock() only.
> They also use fsverity_info::inode to do the key comparison.
>
> Fix this by RCU-delaying the freeing of 'struct fsverity_info' after
> it's been removed from the rhashtable.
>
> Fixes: f77f281b6118 ("fsverity: use a hashtable to find the fsverity_info")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Eric Biggers <ebiggers@xxxxxxxxxx>
> ---
> fs/verity/fsverity_private.h | 15 ++++++++++++++-
> fs/verity/open.c | 13 ++++++++++++-
> 2 files changed, 26 insertions(+), 2 deletions(-)
Applied to https://git.kernel.org/pub/scm/fs/fsverity/linux.git/log/?h=for-current
- Eric