summaryrefslogtreecommitdiff
path: root/include/linux
diff options
context:
space:
mode:
authorEmil Tsalapatis <emil@etsalapatis.com>2026-09-22 17:20:18 +0000
committerAlexei Starovoitov <ast@kernel.org>2026-09-22 19:34:04 +0000
commited6eec97b534979dcf28b40c389cee57bd6561d4 (patch)
tree157cd7369ebe630a71b28c542bc3f205dd72f806 /include/linux
parent0b6e06f9501aacaa3aa555de510eef81371ded95 (diff)
downloadlwn-ed6eec97b534979dcf28b40c389cee57bd6561d4.tar.gz
lwn-ed6eec97b534979dcf28b40c389cee57bd6561d4.zip
bpf: Fix bounds check for skb-backed dynptrs
The skb_pointer_if_linear() function checks whether a memory region of length len starting at offset off into the skb is in the linear area, and returns a pointer to the region if so. The check currently subtracts between skb_headlen and offset of the check, and since skb_headlen is unsigned the subtraction can underflow. This causes the bounds check to spuriously pass and generate an arbitrary pointer of the form *(skb->data + off). The only user of this helper is currently skb-backed BPF dynptr code. Returning the wrong pointer leads to the dynptr erroneously being backed with invalid memory. Ensure the subtraction cannot underflow, and fail the check if it would. Use u64 arithmetic to also prevent overflow when calculating (skb_headlen(skb) - off) since off is unsigned. Fixes: 6f5a630d7c57 ("bpf, net: Introduce skb_pointer_if_linear().") Reported-by: Nicholas Carlini <nicholas@carlini.com> Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev> Link: https://patch.msgid.link/20260922172028.6269-2-emil@etsalapatis.com
Diffstat (limited to 'include/linux')
-rw-r--r--include/linux/skbuff.h5
1 files changed, 4 insertions, 1 deletions
diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 421f6fc45451..c8e21903074c 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -4372,7 +4372,10 @@ skb_header_pointer_careful(const struct sk_buff *skb, int offset,
static inline void * __must_check
skb_pointer_if_linear(const struct sk_buff *skb, int offset, int len)
{
- if (likely(skb_headlen(skb) - offset >= len))
+ unsigned int uoffset = (unsigned int)offset;
+
+ if (likely(uoffset <= skb_headlen(skb) &&
+ (unsigned int)len <= skb_headlen(skb) - uoffset))
return skb->data + offset;
return NULL;
}