From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from fout-a5-smtp.messagingengine.com (fout-a5-smtp.messagingengine.com [103.168.172.148]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1EC002D4816; Sun, 5 Apr 2026 17:05:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=103.168.172.148 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775408740; cv=none; b=Va4nQajlxdSQVTA7rCYv76Wukw63LERgSltbzFcbiaGqSR8HO+Nf65FNhM17pZLXyglmKHDB3PeTvHGJcHt0G3+/uYHu0glGaKg28r9lwBIABC8mCTg9Q8qzSkrfue/cqPrFBWFzwATRinkCsxCOTJw3cqrxoKHcJBgbralBFws= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775408740; c=relaxed/simple; bh=KUTDRpKXu1qzyR66Tdf+Xqwj7Eo+bHgf3KoNcyZVwSs=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=MMjeGr5hYGRVdej2WsLFgngpbJ9P469uQLsW3wj7iQllVwPXLLAC6GkJbhTx7cAfpoKMfbs5d60xQ2N7vUpHWZtebyeBtdosO5XE16alqmpmrv+KXizhu++ciiyLNgZ8w7sRkbOrabtbgVuV70Yao6kIvyrzFWzTzshMRVLkgWU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=pobox.com; spf=pass smtp.mailfrom=pobox.com; dkim=pass (2048-bit key) header.d=pobox.com header.i=@pobox.com header.b=rW0Ze3Dc; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=pysYr8aA; arc=none smtp.client-ip=103.168.172.148 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=pobox.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=pobox.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=pobox.com header.i=@pobox.com header.b="rW0Ze3Dc"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="pysYr8aA" Received: from phl-compute-06.internal (phl-compute-06.internal [10.202.2.46]) by mailfout.phl.internal (Postfix) with ESMTP id 29E16EC0022; Sun, 5 Apr 2026 13:05:38 -0400 (EDT) Received: from phl-frontend-02 ([10.202.2.161]) by phl-compute-06.internal (MEProxy); Sun, 05 Apr 2026 13:05:38 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pobox.com; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm1; t=1775408738; x=1775495138; bh=DkFv7NiVxZ75fED9VjTy1smI+uxt/AWq4k6gjOkay3U=; b= rW0Ze3DcfD0fTuS+Ur0VoNgxXUcYOJiBqShGSjqzBoTPdss1MNp2u5sIyJLQSL4U i0FotyKK6IYjRA9r6ar6pCwmzTfyextI4GIDF5Nie2pL4DGXvSJTY4Ssz7xRqoLK TiAsgquRsxUMIBN9VwFh+lPqx7sJbmlJTrDUvABpIMhxpGWs2zH/veCjBYdnJYWe 9BGAdJe31ZozzEmN5+kGdFQ39phJVB6WU7GrlxrgbFm/ZaxVMpQWnGCcNWUyKXUl KxcEkcZTQoho7AlpWW7Zz6GqvdAPlU8K/Cj9CcL22zGdQayc5karBVJ6ChzJ9qLY R38tF9JoekvgndIGY9sShQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1775408738; x= 1775495138; bh=DkFv7NiVxZ75fED9VjTy1smI+uxt/AWq4k6gjOkay3U=; b=p ysYr8aAaMjAccDOqoISy0KokqN+zvxNUT9bXuh7UDGOflmuMck3Y3+3H52mJbxPv EIapXVk4rmDGUC/TcUgqpQyLLd1aYY6wgUT/c7cAIgo6S74md3qht9Npq2Q8xACR a9JUeyZGbeMmjzxtL2ei46Ckl9rKE13b2mhW8k9BlDJf5yctoJaqQX3bqWLBELXz OA7FwbwNvYzrB4cHMNKcczfhymJMSm0hbAk/kawx/jJVkmKyyfe/5FFMdTzkL49U 5Si2q761EYoISrXaKfS2WlLTjMsQBYwdNO+cLJGKLsAk7OFZzaK1V8JONGMDrjlw FVFeMkMPaWl/542VqewPQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefhedrtddtgdduheefvdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpuffrtefokffrpgfnqfghnecuuegr ihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenucfjug hrpefkffggfgfuvfevfhfhjggtgfesthejredttddvjeenucfhrhhomhepfdeurghrrhih ucfmrdcupfgrthhhrghnfdcuoegsrghrrhihnhesphhosghogidrtghomheqnecuggftrf grthhtvghrnhepheejvddufeehheeglefffedtueegvddvhfduueffheeviefgveeihfel hfeluedtnecuffhomhgrihhnpehkvghrnhgvlhdrohhrghdpghhithhhuhgsrdgtohhmpd igrdgtohhmnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhho mhepsggrrhhrhihnsehpohgsohigrdgtohhmpdhnsggprhgtphhtthhopeeipdhmohguvg epshhmthhpohhuthdprhgtphhtthhopehtohhmrghsiieskhhrrghmkhhofidrshhkihdp rhgtphhtthhopehgrhgvghhkhheslhhinhhugihfohhunhgurghtihhonhdrohhrghdprh gtphhtthhopehsthgrsghlvgesvhhgvghrrdhkvghrnhgvlhdrohhrghdprhgtphhtthho pehvihhrohesiigvnhhivhdrlhhinhhugidrohhrghdruhhkpdhrtghpthhtohepsghrrg hunhgvrheskhgvrhhnvghlrdhorhhgpdhrtghpthhtoheplhhinhhugidqfhhsuggvvhgv lhesvhhgvghrrdhkvghrnhgvlhdrohhrgh X-ME-Proxy: Feedback-ID: i6289494f:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sun, 5 Apr 2026 13:05:36 -0400 (EDT) Message-ID: <7ab3b184-8d9f-465d-b678-4def48cc2a9f@pobox.com> Date: Sun, 5 Apr 2026 10:05:35 -0700 Precedence: bulk X-Mailing-List: stable@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 6.6.y v2 0/2] Fix `fremovexattr` missing `fdput` To: Tomasz Kramkowski , Greg Kroah-Hartman , stable@vger.kernel.org Cc: Alexander Viro , Christian Brauner , linux-fsdevel@vger.kernel.org References: <20260405114505.568530-1-tomasz@kramkow.ski> Content-Language: en-US From: "Barry K. Nathan" In-Reply-To: <20260405114505.568530-1-tomasz@kramkow.ski> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 4/5/26 04:45, Tomasz Kramkowski wrote: > As discussed, a v2 which includes the revert from the previous version > [0] and a new attempt at backporiting the upstream change which doesn't > cause the regression introduced in the first attempt[1]. > > In total, this fixes the missing `fdput` in the `fremovexattr` > `copy_from_user` error path that the backport was intended for. > > I tested both the error case and the happy case in qemu. > > [0]: https://lore.kernel.org/stable/20260404112219.389495-1-tomasz@kramkow.ski/ > [1]: https://lore.kernel.org/stable/tencent_72B5370E2D4C4AC319ED4F0DCB479CA4B406@qq.com/ > > Al Viro (1): > xattr: switch to CLASS(fd) > > Tomasz Kramkowski (1): > Revert "xattr: switch to CLASS(fd)" > > fs/xattr.c | 10 +++++++++- > 1 file changed, 9 insertions(+), 1 deletion(-) > I tested the following two (groups of) proof-of-concept exploits against 6.6.130, 6.6.132, and 6.6.132 + this patch series: 1. "CVE-2024-14027 - SlopSploit" proof-of-concept exploit for the bug fixed by the original mainline commit. This only works on i386 kernels, so I tested with i386 kernels on amd64 hardware. https://github.com/lcfr-eth/CVE-2024-14027_slop (I used exploit.c. For me, the exploit never reached its intended goal of allowing a normal user to read /etc/shadow, but as far as I can tell it still causes a parade of oopses on vulnerable i386 kernels but no oopses on invulnerable i386 kernels. So it's still a good test of whether this patch series works.) 2. Brad Spengler's proof-of-concept exploits for the 6.6.132 regression, posted on Twitter (I tested on i386 and amd64 kernels, on amd64 hardware): https://x.com/spendergrsec/status/2040049852793450561 (Note that one of these has a missing parameter, but it's easy enough to fix.) Test results: 6.6.130: #1 causes oopses (but not #2) 6.6.132: #2 causes oopses (but not #1) 6.6.132 + this patch series: Neither #1 nor #2 cause oopses So, at least in my testing, this patch series successfully fixes both the old and new bugs (both CVE-2024-14027 and the 6.6.132 regression). Tested-by: Barry K. Nathan -- -Barry K. Nathan