Jiri Olsa
19b8833055
UPSTREAM: bpf: Add extra path pointer check to d_path helper
...
[ Upstream commit f46fab0e36e611a2389d3843f34658c849b6bd60 ]
Anastasios reported crash on stable 5.15 kernel with following
BPF attached to lsm hook:
SEC("lsm.s/bprm_creds_for_exec")
int BPF_PROG(bprm_creds_for_exec, struct linux_binprm *bprm)
{
struct path *path = &bprm->executable->f_path;
char p[128] = { 0 };
bpf_d_path(path, p, 128);
return 0;
}
But bprm->executable can be NULL, so bpf_d_path call will crash:
BUG: kernel NULL pointer dereference, address: 0000000000000018
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1 ] PREEMPT SMP DEBUG_PAGEALLOC NOPTI
...
RIP: 0010:d_path+0x22/0x280
...
Call Trace:
<TASK>
bpf_d_path+0x21/0x60
bpf_prog_db9cf176e84498d9_bprm_creds_for_exec+0x94/0x99
bpf_trampoline_6442506293_0+0x55/0x1000
bpf_lsm_bprm_creds_for_exec+0x5/0x10
security_bprm_creds_for_exec+0x29/0x40
bprm_execve+0x1c1/0x900
do_execveat_common.isra.0+0x1af/0x260
__x64_sys_execve+0x32/0x40
It's problem for all stable trees with bpf_d_path helper, which was
added in 5.9.
This issue is fixed in current bpf code, where we identify and mark
trusted pointers, so the above code would fail even to load.
For the sake of the stable trees and to workaround potentially broken
verifier in the future, adding the code that reads the path object from
the passed pointer and verifies it's valid in kernel space.
Fixes: 6e22ab9da793 ("bpf: Add d_path helper")
Reported-by: Anastasios Papagiannis <tasos.papagiannnis@gmail.com>
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: I865e5c3a9c4d0268e9cbb35a74a162898c1c0a7e
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Stanislav Fomichev <sdf@google.com>
Acked-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/bpf/20230606181714.532998-1-jolsa@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:41 -08:00
..
bpf
UPSTREAM: bpf, netns: Fix build without CONFIG_INET
2026-01-14 18:13:18 -08:00
cgroup
UPSTREAM: cgroup: remove redundant kernfs_activate in cgroup_setup_root()
2026-01-14 18:13:14 -08:00
configs
debug
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
dma
Merge tag 'ASB-2024-10-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-10-09 18:08:17 +00:00
events
UPSTREAM: bpf: Fail PERF_EVENT_IOC_SET_BPF when bpf_get_[stack|stackid] cannot work
2026-01-14 18:12:08 -08:00
gcov
gcov: add support for GCC 15
2025-12-03 12:45:19 +01:00
irq
Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:23:13 +03:00
livepatch
UPSTREAM: ftrace: Introduce PERMANENT ftrace_ops flag
2025-12-23 13:35:45 -08:00
locking
Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-06-30 10:49:17 +03:00
power
Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:17:54 +03:00
printk
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
rcu
BACKPORT: rcu-tasks: Add a grace-period start time for throttling and debug
2026-01-14 18:13:22 -08:00
sched
UPSTREAM: sched/core: Add function to sample state of locked-down task
2026-01-14 18:13:18 -08:00
time
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
trace
UPSTREAM: bpf: Add extra path pointer check to d_path helper
2026-02-01 20:44:41 -08:00
.gitignore
acct.c
acct: perform last write from workqueue
2025-03-13 12:43:26 +01:00
async.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
audit.c
audit: Send netlink ACK before setting connection in auditd_set
2024-02-23 08:24:54 +01:00
audit.h
audit_fsnotify.c
audit: fix potential double free on error path from fsnotify_add_inode_mark
2022-09-05 10:27:38 +02:00
audit_tree.c
audit_watch.c
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c
audit: fix possible soft lockup in __audit_inode_child()
2023-09-23 10:59:46 +02:00
backtracetest.c
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-04-20 12:07:32 +02:00
bounds.c
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
2024-05-02 16:18:37 +02:00
capability.c
cfi.c
compat.c
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c
hrtimers: Handle CPU state correctly on hotplug
2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
Revert "cred: switch to using atomic_long_t"
2024-01-03 17:00:08 +00:00
delayacct.c
dma.c
exec_domain.c
exit.c
UPSTREAM: umd: Track user space drivers with struct pid
2026-01-14 18:12:15 -08:00
extable.c
UPSTREAM: bpf: Remove bpf_image tree
2025-12-23 13:36:07 -08:00
fail_function.c
kernel/fail_function: fix memory leak with using debugfs_lookup()
2023-03-11 16:44:15 +01:00
fork.c
fork: adjust sysctl_max_threads definition to match prototype
2026-02-01 20:37:34 -08:00
freezer.c
futex.c
Merge 5.4.246 into android11-5.4-lts
2023-06-20 19:13:58 +00:00
gen_kheaders.sh
Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina
2025-04-12 09:31:28 +00:00
groups.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
hung_task.c
kernel/hung_task.c: make type annotations consistent
2026-02-01 20:38:49 -08:00
iomem.c
irq_work.c
UPSTREAM: irq_work: Convert flags to atomic_t
2025-12-23 13:35:39 -08:00
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: fix a memory leak in crash_shrink_memory()
2023-07-27 08:37:10 +02:00
kexec_elf.c
kexec: initialize ELF lowest address to ULONG_MAX
2025-04-10 14:29:41 +02:00
kexec_file.c
kexec: support purgatories with .text.hot sections
2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c
kheaders: Use array declaration instead of char
2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
ksysfs.c
kthread.c
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
latencytop.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
Makefile
UPSTREAM: bpf: Add kernel module with user mode driver that populates bpffs.
2026-01-14 18:12:16 -08:00
module-internal.h
module.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c
padata: Reset next CPU when reorder sequence wraps around
2025-10-29 14:00:01 +01:00
panic.c
panic: Flush kernel log buffer at the end
2024-04-13 12:51:37 +02:00
params.c
module: ensure that kobject_put() is safe for module type kobjects
2025-06-04 14:32:27 +02:00
pid.c
Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-12-04 19:21:35 +02:00
pid_namespace.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
profile.c
profiling: fix shift too large makes kernel panic
2022-08-25 11:18:02 +02:00
ptrace.c
ptrace: Reimplement PTRACE_KILL by always sending SIGKILL
2022-06-14 18:11:24 +02:00
range.c
reboot.c
This is the 5.4.262 stable release
2023-11-29 10:18:14 +00:00
relay.c
relayfs: fix out-of-bounds access in relay_file_read
2023-05-17 11:35:58 +02:00
resource.c
resource: fix region_intersects() vs add_memory_driver_managed()
2024-11-08 16:20:46 +01:00
rseq.c
scs.c
seccomp.c
seccomp: Remove bogus __user annotations
2026-02-01 20:39:03 -08:00
signal.c
Merge tag 'ASB-2024-12-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-12-17 03:24:53 +02:00
smp.c
Merge tag 'ASB-2024-11-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-11-08 15:36:32 +00:00
smpboot.c
smpboot.h
softirq.c
Revert "tasklet: Introduce new initialization API"
2025-03-13 17:21:46 +00:00
stackleak.c
stackleak: let stack_erasing_sysctl take a kernel pointer buffer
2026-02-01 20:38:37 -08:00
stacktrace.c
stop_machine.c
sys.c
Merge 5.4.272 into android11-5.4-lts
2024-04-05 12:37:33 +00:00
sys_ni.c
BACKPORT: epoll: wire up syscall epoll_pwait2
2025-12-22 07:42:50 +02:00
sysctl-test.c
sysctl.c
bpf, sysctl: Let bpf_stats_handler take a kernel pointer buffer
2026-02-01 20:37:19 -08:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
UPSTREAM: module: Fix up module_notifier return values
2026-01-14 18:12:53 -08:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
BACKPORT: umh: Separate the user mode driver and the user mode helper support
2026-01-14 18:12:14 -08:00
up.c
user-return-notifier.c
user.c
user_namespace.c
usermode_driver.c
UPSTREAM: bpf: Fix umd memory leak in copy_process()
2026-01-14 18:12:50 -08:00
utsname.c
utsname_sysctl.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
watchdog.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
watchdog_hld.c
watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
2024-08-19 05:33:39 +02:00
workqueue.c
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
workqueue_internal.h