7.8

CVE-2026-68148

fscrypt: Add missing superblock check in find_or_insert_direct_key()

In the Linux kernel, the following vulnerability has been resolved:

fscrypt: Add missing superblock check in find_or_insert_direct_key()

The legacy 'fscrypt_direct_keys' table caches master keys that are used
by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY.
It's just a global table for all filesystems (since the keys can be
provided by the legacy process-subscribed keyrings mechanism, which
makes it difficult to reuse super_block::s_master_keys).

The entries in it ('struct fscrypt_direct_key') do contain a super_block
pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when
the last inode that references the key is evicted.

However, when finding the fscrypt_direct_key for an inode, we weren't
actually comparing the super_block pointer.  As a result, inodes with
different super_blocks could point to the same fscrypt_direct_key.  That
could extend the lifetime of a fscrypt_direct_key beyond the
super_block it points to, causing a use-after-free later.

Fix this by creating distinct fscrypt_direct_key structs for distinct
super_block structs.

Note that this problem doesn't exist in the v2 policy equivalent
("per-mode keys"), since the data structures there are per super_block.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 22e9947a4b2ba255888541bd0111cf00b9b16586
Version < 965b5bc8cf5031225e057979ce660fec2bd5fbfc
Status affected
Version 22e9947a4b2ba255888541bd0111cf00b9b16586
Version < 330249609b70778094a7a36f5b6bcfa6362121d4
Status affected
Version 22e9947a4b2ba255888541bd0111cf00b9b16586
Version < deff41898a5ae3a47db5fa1896a494aa95efda5d
Status affected
Version 22e9947a4b2ba255888541bd0111cf00b9b16586
Version < 95376fe9c145be35566991df99c53134943d992f
Status affected
Version 22e9947a4b2ba255888541bd0111cf00b9b16586
Version < 466f187b501a5ac8e1ea2ccf3ccd5c46108d8830
Status affected
Version 22e9947a4b2ba255888541bd0111cf00b9b16586
Version < b5fa40226e71c17847b9ff2816c6ca4133d0d994
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.1
Status affected
Version 0
Version < 6.1
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.006
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4
https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d
https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f
https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830
https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994
https://git.kernel.org/stable/c/965b5bc8cf5031225e057979ce660fec2bd5fbfc