From: Jarkko Sakkinen <jarkko@kernel.org>
To: Chengfeng Ye <nicoyip.dev@gmail.com>
Cc: James Bottomley <James.Bottomley@hansenpartnership.com>,
Mimi Zohar <zohar@linux.ibm.com>,
David Howells <dhowells@redhat.com>,
Paul Moore <paul@paul-moore.com>,
James Morris <jmorris@namei.org>,
"Serge E. Hallyn" <serge@hallyn.com>,
Roberto Sassu <roberto.sassu@huawei.com>,
linux-integrity@vger.kernel.org, keyrings@vger.kernel.org,
linux-security-module@vger.kernel.org,
linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH] KEYS: trusted: Fix TPM teardown ordering
Date: Mon, 10 Aug 2026 18:25:53 +0300 [thread overview]
Message-ID: <anntgVGE0cUzQxjJ@kernel.org> (raw)
In-Reply-To: <20260731140925.2973492-1-nicoyip.dev@gmail.com>
On Fri, Jul 31, 2026 at 10:09:24PM +0800, Chengfeng Ye wrote:
> trusted_tpm_exit() drops the TPM chip reference and frees the digest
> array before unregistering the trusted key type. key_type_lookup()
> holds key_types_sem for reading until the key operation finishes, while
> unregister_key_type() takes it for writing. It therefore provides the
> synchronization point that must precede backend teardown.
>
> The current order permits this interleaving:
>
> CPU 0 CPU 1
> trusted_tpm_exit() key_type_lookup("trusted")
> put_device(&chip->dev) trusted_tpm_seal()
> kfree(digests) pcrlock()
> unregister_key_type() tpm_pcr_extend(..., digests)
>
> CPU 1 can consequently dereference the freed digest array. The chip can
> also be released before callbacks stop using it.
>
> KASAN reported:
>
> BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200
> Read of size 2 at addr ffff88810872d000 by task poc/89
> Call Trace:
> tpm_pcr_extend+0x1f0/0x200
> pcrlock+0x42/0x70 [trusted]
> trusted_tpm_seal+0x1b6/0x570 [trusted]
> trusted_instantiate+0x293/0x340 [trusted]
> __key_instantiate_and_link+0xb2/0x2b0
> __key_create_or_update+0x61e/0xb50
> __do_sys_add_key+0x1b8/0x310
> Allocated by task 88:
> __kmalloc_noprof+0x1a7/0x490
> do_one_initcall+0xa1/0x390
> do_init_module+0x2df/0x840
> Freed by task 90:
> kfree+0x131/0x3c0
> trusted_tpm_exit+0x59/0xa0 [trusted]
> __do_sys_delete_module+0x346/0x510
>
> Move unregister_key_type() before releasing either resource. This stops
> new lookups and waits for in-flight key operations to finish before the
> backend state is destroyed.
Thank for the great report.
>
> Fixes: 0b6cf6b97b7e ("tpm: pass an array of tpm_extend_digest structures to tpm_pcr_extend()")
> Cc: stable@vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
> ---
> security/keys/trusted-keys/trusted_tpm1.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/security/keys/trusted-keys/trusted_tpm1.c b/security/keys/trusted-keys/trusted_tpm1.c
> index 13513819991e..8f57c6111e7e 100644
> --- a/security/keys/trusted-keys/trusted_tpm1.c
> +++ b/security/keys/trusted-keys/trusted_tpm1.c
> @@ -987,9 +987,9 @@ static int __init trusted_tpm_init(void)
> static void trusted_tpm_exit(void)
> {
> if (chip) {
> + unregister_key_type(&key_type_trusted);
> put_device(&chip->dev);
> kfree(digests);
> - unregister_key_type(&key_type_trusted);
> }
> }
>
> --
> 2.43.0
>
Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>
BR, Jarkko
prev parent reply other threads:[~2026-08-10 15:26 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 14:09 [PATCH] KEYS: trusted: Fix TPM teardown ordering Chengfeng Ye
2026-08-10 15:25 ` Jarkko Sakkinen [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anntgVGE0cUzQxjJ@kernel.org \
--to=jarkko@kernel.org \
--cc=James.Bottomley@hansenpartnership.com \
--cc=dhowells@redhat.com \
--cc=jmorris@namei.org \
--cc=keyrings@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=nicoyip.dev@gmail.com \
--cc=paul@paul-moore.com \
--cc=roberto.sassu@huawei.com \
--cc=serge@hallyn.com \
--cc=stable@vger.kernel.org \
--cc=zohar@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.