No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jiayuan Chen d685096c81 ppp: Fix KMSAN uninit-value warning with bpf
[ Upstream commit 4c2d14c40a68678d885eab4008a0129646805bae ]

Syzbot caught an "KMSAN: uninit-value" warning [1], which is caused by the
ppp driver not initializing a 2-byte header when using socket filter.

The following code can generate a PPP filter BPF program:
'''
struct bpf_program fp;
pcap_t *handle;
handle = pcap_open_dead(DLT_PPP_PPPD, 65535);
pcap_compile(handle, &fp, "ip and outbound", 0, 0);
bpf_dump(&fp, 1);
'''
Its output is:
'''
(000) ldh [2]
(001) jeq #0x21 jt 2 jf 5
(002) ldb [0]
(003) jeq #0x1 jt 4 jf 5
(004) ret #65535
(005) ret #0
'''
Wen can find similar code at the following link:
https://github.com/ppp-project/ppp/blob/master/pppd/options.c#L1680
The maintainer of this code repository is also the original maintainer
of the ppp driver.

As you can see the BPF program skips 2 bytes of data and then reads the
'Protocol' field to determine if it's an IP packet. Then it read the first
byte of the first 2 bytes to determine the direction.

The issue is that only the first byte indicating direction is initialized
in current ppp driver code while the second byte is not initialized.

For normal BPF programs generated by libpcap, uninitialized data won't be
used, so it's not a problem. However, for carefully crafted BPF programs,
such as those generated by syzkaller [2], which start reading from offset
0, the uninitialized data will be used and caught by KMSAN.

[1] https://syzkaller.appspot.com/bug?extid=853242d9c9917165d791
[2] https://syzkaller.appspot.com/text?tag=ReproC&x=11994913980000

Cc: Paul Mackerras <paulus@samba.org>
Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Reported-by: syzbot+853242d9c9917165d791@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/bpf/000000000000dea025060d6bc3bc@google.com/
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20250228141408.393864-1-jiayuan.chen@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-03-13 12:43:30 +01:00
arch x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63 2025-03-13 12:43:27 +01:00
block partitions: mac: fix handling of bogus partition table 2025-03-13 12:43:16 +01:00
certs
crypto crypto: testmgr - some more fixes to RSA test vectors 2025-03-13 12:43:21 +01:00
Documentation dt-bindings: mmc: controller: clarify the address-cells description 2025-03-13 12:42:53 +01:00
drivers ppp: Fix KMSAN uninit-value warning with bpf 2025-03-13 12:43:30 +01:00
fs btrfs: avoid monopolizing a core when activating a swap file 2025-03-13 12:43:19 +01:00
include net: extract port range fields from fl_flow_key 2025-03-13 12:43:23 +01:00
init
ipc
kernel acct: perform last write from workqueue 2025-03-13 12:43:26 +01:00
lib
LICENSES
mm mm/page_alloc: fix uninitialized variable 2025-03-13 12:43:28 +01:00
net llc: do not use skb_get() before dev_queue_xmit() 2025-03-13 12:43:29 +01:00
samples
scripts kbuild: Move -Wenum-enum-conversion to W=2 2025-03-13 12:43:09 +01:00
security ima: Fix use-after-free on a dentry's dname.name 2025-03-13 12:43:19 +01:00
sound ALSA: hda/realtek: update ALC222 depop optimize 2025-03-13 12:43:27 +01:00
tools perf bench: Fix undefined behavior in cmpworker() 2025-03-13 12:43:08 +01:00
usr
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS
Makefile kbuild: userprogs: use correct lld when linking through clang 2025-03-13 12:43:04 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.