android_kernel_motorola_sm6375/kernel
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jiri Olsa 19b8833055
UPSTREAM: bpf: Add extra path pointer check to d_path helper
[ Upstream commit f46fab0e36e611a2389d3843f34658c849b6bd60 ]

Anastasios reported crash on stable 5.15 kernel with following
BPF attached to lsm hook:

  SEC("lsm.s/bprm_creds_for_exec")
  int BPF_PROG(bprm_creds_for_exec, struct linux_binprm *bprm)
  {
          struct path *path = &bprm->executable->f_path;
          char p[128] = { 0 };

          bpf_d_path(path, p, 128);
          return 0;
  }

But bprm->executable can be NULL, so bpf_d_path call will crash:

  BUG: kernel NULL pointer dereference, address: 0000000000000018
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  PGD 0 P4D 0
  Oops: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC NOPTI
  ...
  RIP: 0010:d_path+0x22/0x280
  ...
  Call Trace:
   <TASK>
   bpf_d_path+0x21/0x60
   bpf_prog_db9cf176e84498d9_bprm_creds_for_exec+0x94/0x99
   bpf_trampoline_6442506293_0+0x55/0x1000
   bpf_lsm_bprm_creds_for_exec+0x5/0x10
   security_bprm_creds_for_exec+0x29/0x40
   bprm_execve+0x1c1/0x900
   do_execveat_common.isra.0+0x1af/0x260
   __x64_sys_execve+0x32/0x40

It's problem for all stable trees with bpf_d_path helper, which was
added in 5.9.

This issue is fixed in current bpf code, where we identify and mark
trusted pointers, so the above code would fail even to load.

For the sake of the stable trees and to workaround potentially broken
verifier in the future, adding the code that reads the path object from
the passed pointer and verifies it's valid in kernel space.

Fixes: 6e22ab9da793 ("bpf: Add d_path helper")
Reported-by: Anastasios Papagiannis <tasos.papagiannnis@gmail.com>
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: I865e5c3a9c4d0268e9cbb35a74a162898c1c0a7e
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Stanislav Fomichev <sdf@google.com>
Acked-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/bpf/20230606181714.532998-1-jolsa@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:41 -08:00
..
bpf UPSTREAM: bpf, netns: Fix build without CONFIG_INET 2026-01-14 18:13:18 -08:00
cgroup UPSTREAM: cgroup: remove redundant kernfs_activate in cgroup_setup_root() 2026-01-14 18:13:14 -08:00
configs
debug BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault 2026-01-14 18:13:21 -08:00
dma Merge tag 'ASB-2024-10-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-10-09 18:08:17 +00:00
events UPSTREAM: bpf: Fail PERF_EVENT_IOC_SET_BPF when bpf_get_[stack|stackid] cannot work 2026-01-14 18:12:08 -08:00
gcov gcov: add support for GCC 15 2025-12-03 12:45:19 +01:00
irq Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:23:13 +03:00
livepatch UPSTREAM: ftrace: Introduce PERMANENT ftrace_ops flag 2025-12-23 13:35:45 -08:00
locking Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-06-30 10:49:17 +03:00
power Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:17:54 +03:00
printk BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
rcu BACKPORT: rcu-tasks: Add a grace-period start time for throttling and debug 2026-01-14 18:13:22 -08:00
sched UPSTREAM: sched/core: Add function to sample state of locked-down task 2026-01-14 18:13:18 -08:00
time BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
trace UPSTREAM: bpf: Add extra path pointer check to d_path helper 2026-02-01 20:44:41 -08:00
.gitignore
acct.c acct: perform last write from workqueue 2025-03-13 12:43:26 +01:00
async.c treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
audit.c audit: Send netlink ACK before setting connection in auditd_set 2024-02-23 08:24:54 +01:00
audit.h
audit_fsnotify.c audit: fix potential double free on error path from fsnotify_add_inode_mark 2022-09-05 10:27:38 +02:00
audit_tree.c
audit_watch.c audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare() 2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c audit: fix possible soft lockup in __audit_inode_child() 2023-09-23 10:59:46 +02:00
backtracetest.c treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD() 2023-04-20 12:07:32 +02:00
bounds.c bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS 2024-05-02 16:18:37 +02:00
capability.c
cfi.c
compat.c sched_getaffinity: don't assume 'cpumask_size()' is fully initialized 2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c hrtimers: Handle CPU state correctly on hotplug 2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c Revert "cred: switch to using atomic_long_t" 2024-01-03 17:00:08 +00:00
delayacct.c
dma.c
exec_domain.c
exit.c UPSTREAM: umd: Track user space drivers with struct pid 2026-01-14 18:12:15 -08:00
extable.c UPSTREAM: bpf: Remove bpf_image tree 2025-12-23 13:36:07 -08:00
fail_function.c kernel/fail_function: fix memory leak with using debugfs_lookup() 2023-03-11 16:44:15 +01:00
fork.c fork: adjust sysctl_max_threads definition to match prototype 2026-02-01 20:37:34 -08:00
freezer.c
futex.c Merge 5.4.246 into android11-5.4-lts 2023-06-20 19:13:58 +00:00
gen_kheaders.sh Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina 2025-04-12 09:31:28 +00:00
groups.c BACKPORT: mm: remove the pgprot argument to __vmalloc 2026-01-14 17:48:09 -08:00
hung_task.c kernel/hung_task.c: make type annotations consistent 2026-02-01 20:38:49 -08:00
iomem.c
irq_work.c UPSTREAM: irq_work: Convert flags to atomic_t 2025-12-23 13:35:39 -08:00
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c kexec: fix a memory leak in crash_shrink_memory() 2023-07-27 08:37:10 +02:00
kexec_elf.c kexec: initialize ELF lowest address to ULONG_MAX 2025-04-10 14:29:41 +02:00
kexec_file.c kexec: support purgatories with .text.hot sections 2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c kheaders: Use array declaration instead of char 2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
ksysfs.c
kthread.c BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault 2026-01-14 18:13:21 -08:00
latencytop.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
Makefile UPSTREAM: bpf: Add kernel module with user mode driver that populates bpffs. 2026-01-14 18:12:16 -08:00
module-internal.h
module.c BACKPORT: mm: remove the pgprot argument to __vmalloc 2026-01-14 17:48:09 -08:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c padata: Reset next CPU when reorder sequence wraps around 2025-10-29 14:00:01 +01:00
panic.c panic: Flush kernel log buffer at the end 2024-04-13 12:51:37 +02:00
params.c module: ensure that kobject_put() is safe for module type kobjects 2025-06-04 14:32:27 +02:00
pid.c Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-12-04 19:21:35 +02:00
pid_namespace.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
profile.c profiling: fix shift too large makes kernel panic 2022-08-25 11:18:02 +02:00
ptrace.c ptrace: Reimplement PTRACE_KILL by always sending SIGKILL 2022-06-14 18:11:24 +02:00
range.c
reboot.c This is the 5.4.262 stable release 2023-11-29 10:18:14 +00:00
relay.c relayfs: fix out-of-bounds access in relay_file_read 2023-05-17 11:35:58 +02:00
resource.c resource: fix region_intersects() vs add_memory_driver_managed() 2024-11-08 16:20:46 +01:00
rseq.c
scs.c
seccomp.c seccomp: Remove bogus __user annotations 2026-02-01 20:39:03 -08:00
signal.c Merge tag 'ASB-2024-12-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-12-17 03:24:53 +02:00
smp.c Merge tag 'ASB-2024-11-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-11-08 15:36:32 +00:00
smpboot.c
smpboot.h
softirq.c Revert "tasklet: Introduce new initialization API" 2025-03-13 17:21:46 +00:00
stackleak.c stackleak: let stack_erasing_sysctl take a kernel pointer buffer 2026-02-01 20:38:37 -08:00
stacktrace.c
stop_machine.c
sys.c Merge 5.4.272 into android11-5.4-lts 2024-04-05 12:37:33 +00:00
sys_ni.c BACKPORT: epoll: wire up syscall epoll_pwait2 2025-12-22 07:42:50 +02:00
sysctl-test.c
sysctl.c bpf, sysctl: Let bpf_stats_handler take a kernel pointer buffer 2026-02-01 20:37:19 -08:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c UPSTREAM: module: Fix up module_notifier return values 2026-01-14 18:12:53 -08:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c BACKPORT: umh: Separate the user mode driver and the user mode helper support 2026-01-14 18:12:14 -08:00
up.c
user-return-notifier.c
user.c
user_namespace.c
usermode_driver.c UPSTREAM: bpf: Fix umd memory leak in copy_process() 2026-01-14 18:12:50 -08:00
utsname.c
utsname_sysctl.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
watchdog.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
watchdog_hld.c watchdog/perf: properly initialize the turbo mode timestamp and rearm counter 2024-08-19 05:33:39 +02:00
workqueue.c BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault 2026-01-14 18:13:21 -08:00
workqueue_internal.h