Skip to content

Commit f9b0e10

Browse files
borkmannanakryiko
authored andcommitted
bpf, mprog: Fix maximum program check on mprog attachment
After Paul's recent improvement to syzkaller to improve coverage for bpf_mprog and tcx, it hit a splat that the program limit was surpassed. What happened is that the maximum number of progs got added, followed by another prog add request which adds with BPF_F_BEFORE flag relative to the last program in the array. The idx >= bpf_mprog_max() check in bpf_mprog_attach() still passes because the index is below the maximum but the maximum will be surpassed. We need to add a check upfront for insertions to catch this situation. Fixes: 053c8e1 ("bpf: Add generic attach/detach/query API for multi-progs") Reported-by: [email protected] Reported-by: [email protected] Reported-by: [email protected] Co-developed-by: Nikolay Aleksandrov <[email protected]> Signed-off-by: Nikolay Aleksandrov <[email protected]> Signed-off-by: Daniel Borkmann <[email protected]> Signed-off-by: Andrii Nakryiko <[email protected]> Tested-by: [email protected] Tested-by: [email protected] Link: google/syzkaller#4207 Link: https://lore.kernel.org/bpf/[email protected]
1 parent b80e31b commit f9b0e10

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

kernel/bpf/mprog.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -253,6 +253,9 @@ int bpf_mprog_attach(struct bpf_mprog_entry *entry,
253253
goto out;
254254
}
255255
idx = tidx;
256+
} else if (bpf_mprog_total(entry) == bpf_mprog_max()) {
257+
ret = -ERANGE;
258+
goto out;
256259
}
257260
if (flags & BPF_F_BEFORE) {
258261
tidx = bpf_mprog_pos_before(entry, &rtuple);

0 commit comments

Comments
 (0)