Commit ac6542a
bpf: fix null dereference when computing changes_pkt_data of prog w/o subprogs
bpf_prog_aux->func field might be NULL if program does not have
subprograms except for main sub-program. The fixed commit does
bpf_prog_aux->func access unconditionally, which might lead to null
pointer dereference.
The bug could be triggered by replacing the following BPF program:
SEC("tc")
int main_changes(struct __sk_buff *sk)
{
bpf_skb_pull_data(sk, 0);
return 0;
}
With the following BPF program:
SEC("freplace")
long changes_pkt_data(struct __sk_buff *sk)
{
return bpf_skb_pull_data(sk, 0);
}
bpf_prog_aux instance itself represents the main sub-program,
use this property to fix the bug.
Fixes: 81f6d05 ("bpf: check changes_pkt_data property for extension programs")
Reported-by: kernel test robot <lkp@intel.com>
Reported-by: Dan Carpenter <dan.carpenter@linaro.org>
Closes: https://lore.kernel.org/r/202412111822.qGw6tOyB-lkp@intel.com/
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20241212070711.427443-1-eddyz87@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>1 parent 7d0d673 commit ac6542a
1 file changed
+5
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22193 | 22193 | | |
22194 | 22194 | | |
22195 | 22195 | | |
| 22196 | + | |
22196 | 22197 | | |
22197 | 22198 | | |
22198 | 22199 | | |
| |||
22227 | 22228 | | |
22228 | 22229 | | |
22229 | 22230 | | |
22230 | | - | |
22231 | | - | |
| 22231 | + | |
| 22232 | + | |
| 22233 | + | |
| 22234 | + | |
22232 | 22235 | | |
22233 | 22236 | | |
22234 | 22237 | | |
| |||
0 commit comments