diff options
| author | Daniel Borkmann <daniel@iogearbox.net> | 2026-07-08 09:53:39 +0200 |
|---|---|---|
| committer | Kumar Kartikeya Dwivedi <memxor@gmail.com> | 2026-07-08 20:04:48 +0200 |
| commit | 576bcaa1f5c208af0f590c9622247da87b49c05f (patch) | |
| tree | 31424433a04425895311b6ce754181d35a7fe2a7 /tools/bpf | |
| parent | a2d784869a0f252e1a277db7dc2c16d55694da72 (diff) | |
| download | linux-next-576bcaa1f5c208af0f590c9622247da87b49c05f.tar.gz linux-next-576bcaa1f5c208af0f590c9622247da87b49c05f.zip | |
bpftool: Check EVP_Digest when computing excl_prog_hash
bpftool_prog_sign() ignores the return value of EVP_Digest(). If the
digest computation fails (context allocation failure, or a digest
fetch failure under OpenSSL), EVP_Digest() returns 0 and leaves the
output buffer untouched, but the function still reports success.
Fixes: 40863f4d6ef2 ("bpftool: Add support for signing BPF programs")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Quentin Monnet <qmo@kernel.org>
Link: https://lore.kernel.org/bpf/20260708075343.358712-5-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Diffstat (limited to 'tools/bpf')
| -rw-r--r-- | tools/bpf/bpftool/sign.c | 7 |
1 files changed, 5 insertions, 2 deletions
diff --git a/tools/bpf/bpftool/sign.c b/tools/bpf/bpftool/sign.c index f9b742f4bb10..1257dba8ef2f 100644 --- a/tools/bpf/bpftool/sign.c +++ b/tools/bpf/bpftool/sign.c @@ -175,8 +175,11 @@ int bpftool_prog_sign(struct bpf_load_and_run_opts *opts) goto cleanup; } - EVP_Digest(opts->insns, opts->insns_sz, opts->excl_prog_hash, - &opts->excl_prog_hash_sz, EVP_sha256(), NULL); + if (EVP_Digest(opts->insns, opts->insns_sz, opts->excl_prog_hash, + &opts->excl_prog_hash_sz, EVP_sha256(), NULL) != 1) { + err = -EIO; + goto cleanup; + } bd_out = BIO_new(BIO_s_mem()); if (!bd_out) { |
