Re: fs_put_dax() vs. dax_holder_notify_failure() race

From: John Groves

Date: Wed Oct 07 2026 - 16:00:32 EST




On Wed, Sep 30, 2026, at 9:29 AM, Miklos Szeredi wrote:
> During ->notify_failure() callback will dereference holder. It may be
> NULL at this point, resulting in an Oops, or it may be non-NULL but be
> freed during that call, resulting in UAF.
>
> This affects xfs at this point, but the fuse extent map patchset[1]
> also adds dax failure handling and is affected by this issue.
>
> I think this should be fixed in drivers/dax/super.c, since this will
> be a problem in each user.
>
> Thanks,
> Miklos

I've seen a bunch of variants of this from Sashiko; will give it a proper
review and fix, but some things are higher on my triage pile (e.g. validating
that file ext_maps work as they should, and offering an improved
fault/begin handler.

All of that and more is coming asap...

Thanks,
John