On Sat, Apr 15, 2017 at 09:51:40AM -0700, Linus Torvalds wrote: > On Fri, Apr 14, 2017 at 11:41 PM, Vegard Nossum <vegard.nossum@xxxxxxxxx> wrote: > > > > I'm seeing the same memfd_create/name_to_handle_at/path_lookupat > > use-after-free that Dmitry was seeing here: > > Ok, see if that is gone in current git with commit c0eb027e5aef ("vfs: > don't do RCU lookup of empty pathnames") FWIW, I'm finishing testing of fixes for crap found during the discussion of that stuff last week (making sure that mntns_install() can't be abused into setting ->fs->root/->fs->pwd to dentry of NFS referral and its ilk and doing that in a sane way).