freenode
Kernel & Low-Level

Kernel fixes RCU pathwalk use-after-frees across several filesystems

Christian Brauner patches ext4, ntfs3, tracefs, casefold, and related code so superblock data outlives concurrent RCU lookups after lazy unmount.

Christian Brauner has posted fixes for a family of use-after-free bugs in Linux VFS RCU pathwalk, spanning ext4, ntfs3, tracefs/eventfs, AFS, 9p, and the generic case-insensitive dentry helpers used by ext4, f2fs, and tmpfs. An adjacent IPC namespace setup leak is corrected in the same series.

Since earlier RCU pathwalk hardening, filesystems themselves must free anything still readable from permission checks, dentry revalidation, get_link, hash, and compare only after an RCU grace period. Several did not. Ordinary umount usually hid the races because namespace teardown waits for a grace period before dropping mounts. The last reference can disappear without that wait, for example on close of the last file or chdir out of a lazily unmounted tree. A walker can then still be inside the filesystem while put_super or kill_sb frees what it reads.

Under KASAN the failures show up as null dereferences or slab use-after-free: ext4 symlink resolution touching freed superblock info and extent-status counters; casefold hash and compare reading a unicode map already unloaded; ntfs3 nocase hash and compare hitting freed superblock private data, including on remount when old mount options are dropped immediately; and tracefs d_revalidate reading an eventfs inode freed only after an SRCU grace period, which does not cover plain RCU readers. AFS and 9p had the same pattern; they were accidentally shielded today by an unrelated grace period inside private bdi unregister, which Brauner declined to keep relying on.

The fixes keep the relevant superblock or session state alive across a grace period (and chain RCU after SRCU for eventfs) so concurrent RCU walkers finish safely. The IPC change uses proper kern_unmount teardown so a failed ipc namespace create no longer leaks the mqueue mount and superblock. The issues are tagged for stable backports.