diff options
| author | Yuqi Xu <xuyuqiabc@gmail.com> | 2026-09-19 16:45:02 +0800 |
|---|---|---|
| committer | Alexei Starovoitov <ast@kernel.org> | 2026-09-19 23:25:17 +0000 |
| commit | a11212910cf09b2fe8db9afa41ef60c4f81879c5 (patch) | |
| tree | da0876f6bb109aba8252d5fd537d000d1d67585e /kernel | |
| parent | e3b6cb020e2f034a98068b2d11bcb3db9fff7e42 (diff) | |
| download | linux-a11212910cf09b2fe8db9afa41ef60c4f81879c5.tar.gz linux-a11212910cf09b2fe8db9afa41ef60c4f81879c5.zip | |
bpf: Check params size before reading reserved fields
bpf_crypto_ctx_create() is a kfunc whose second argument is declared
with the __sz annotation, so the verifier only guarantees that
params__sz bytes of params are valid. The function nevertheless reads
params->reserved[0] and params->reserved[1] (offsets 14 and 15) before
comparing params__sz against the size of struct bpf_crypto_params, so a
BPF program can pass a shorter buffer and have the kernel read past the
region that was validated for it.
Move the size check in front of the reserved field reads.
Fixes: 3e1c6f35409f ("bpf: make common crypto API for TC/XDP programs")
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Reviewed-by: Ren Wei <weir@nebusec.ai>
Link: https://patch.msgid.link/4f3ab4b03e79017e215521743996555439bf0bb3.1789802413.git.xuyuqiabc@gmail.com
Diffstat (limited to 'kernel')
| -rw-r--r-- | kernel/bpf/crypto.c | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/kernel/bpf/crypto.c b/kernel/bpf/crypto.c index 51f89cecefb4..3f3fe2450fc6 100644 --- a/kernel/bpf/crypto.c +++ b/kernel/bpf/crypto.c @@ -149,8 +149,9 @@ bpf_crypto_ctx_create(const struct bpf_crypto_params *params, u32 params__sz, const struct bpf_crypto_type *type; struct bpf_crypto_ctx *ctx; - if (!params || params->reserved[0] || params->reserved[1] || - params__sz != sizeof(struct bpf_crypto_params)) { + if (!params || + params__sz != sizeof(struct bpf_crypto_params) || + params->reserved[0] || params->reserved[1]) { *err = -EINVAL; return NULL; } |
