Toke Høiland-Jørgensen
21e5fa4688
bpf: Fix stackmap overflow check on 32-bit arches
...
[ Upstream commit 7a4b21250bf79eef26543d35bd390448646c536b ]
The stackmap code relies on roundup_pow_of_two() to compute the number
of hash buckets, and contains an overflow check by checking if the
resulting value is 0. However, on 32-bit arches, the roundup code itself
can overflow by doing a 32-bit left-shift of an unsigned long value,
which is undefined behaviour, so it is not guaranteed to truncate
neatly. This was triggered by syzbot on the DEVMAP_HASH type, which
contains the same check, copied from the hashtab code.
The commit in the fixes tag actually attempted to fix this, but the fix
did not account for the UB, so the fix only works on CPUs where an
overflow does result in a neat truncation to zero, which is not
guaranteed. Checking the value before rounding does not have this
problem.
Fixes: 6183f4d3a0a2 ("bpf: Check for integer overflow when using roundup_pow_of_two()")
Signed-off-by: Toke Høiland-Jørgensen <toke@redhat.com>
Reviewed-by: Bui Quang Minh <minhquangbui99@gmail.com>
Message-ID: <20240307120340.99577-4-toke@redhat.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2024-03-26 18:22:17 -04:00
..
bpf
bpf: Fix stackmap overflow check on 32-bit arches
2024-03-26 18:22:17 -04:00
cgroup
cgroup: Remove duplicates in cgroup v1 tasks file
2023-10-25 11:53:19 +02:00
configs
debug
kdb: Fix a potential buffer overflow in kdb_local()
2024-01-25 14:34:32 -08:00
dma
dma-mapping: clear dev->dma_mem to NULL after freeing it
2024-01-25 14:34:25 -08:00
events
perf: Fix the nr_addr_filters fix
2024-02-23 08:25:03 +01:00
gcov
gcov: add support for checksum field
2023-01-18 11:41:42 +01:00
irq
genirq/generic_chip: Make irq_remove_generic_chip() irqdomain aware
2023-11-28 16:50:18 +00:00
livepatch
livepatch: fix race between fork and KLP transition
2022-10-26 13:22:18 +02:00
locking
locking/ww_mutex/test: Fix potential workqueue corruption
2023-11-28 16:50:13 +00:00
power
PM: hibernate: Enforce ordering during image compression/decompression
2024-02-23 08:24:48 +01:00
printk
rcu
rcu: Suppress smp_processor_id() complaint in synchronize_rcu_expedited_wait()
2023-03-11 16:43:54 +01:00
sched
sched/rt: Disallow writing invalid values to sched_rt_period_us
2024-03-01 13:13:33 +01:00
time
timekeeping: Fix cross-timestamp interpolation for non-x86
2024-03-26 18:22:14 -04:00
trace
tracing: Inform kmemleak of saved_cmdlines allocation
2024-02-23 08:25:13 +01:00
.gitignore
acct.c
acct: fix potential integer overflow in encode_comp_t()
2023-01-18 11:41:34 +01:00
async.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
audit.c
audit: Send netlink ACK before setting connection in auditd_set
2024-02-23 08:24:54 +01:00
audit.h
audit_fsnotify.c
audit: fix potential double free on error path from fsnotify_add_inode_mark
2022-09-05 10:27:38 +02:00
audit_tree.c
audit_watch.c
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c
audit: fix possible soft lockup in __audit_inode_child()
2023-09-23 10:59:46 +02:00
backtracetest.c
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-04-20 12:07:32 +02:00
bounds.c
capability.c
compat.c
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c
hrtimers: Push pending hrtimers away from outgoing CPU earlier
2023-12-13 18:18:09 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
cred: switch to using atomic_long_t
2023-12-20 15:41:18 +01:00
delayacct.c
dma.c
exec_domain.c
exit.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
extable.c
kernel/extable.c: use address-of operator on section symbols
2023-06-09 10:29:01 +02:00
fail_function.c
kernel/fail_function: fix memory leak with using debugfs_lookup()
2023-03-11 16:44:15 +01:00
fork.c
kernel/fork: beware of __put_task_struct() calling context
2023-09-23 11:00:03 +02:00
freezer.c
futex.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
gen_kheaders.sh
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: fix a memory leak in crash_shrink_memory()
2023-07-27 08:37:10 +02:00
kexec_elf.c
kexec_file.c
kexec: support purgatories with .text.hot sections
2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c
kheaders: Use array declaration instead of char
2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c
x86/kprobes: Fix arch_check_optimized_kprobe check within optimized_kprobe range
2023-03-11 16:44:02 +01:00
ksysfs.c
kthread.c
latencytop.c
Makefile
module-internal.h
module.c
modules: only allow symbol_get of EXPORT_SYMBOL_GPL modules
2023-09-23 10:59:36 +02:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c
crypto: pcrypt - Fix hungtask for PADATA_RESET
2023-11-28 16:50:14 +00:00
panic.c
exit: Use READ_ONCE() for all oops/warn limit reads
2023-02-06 07:52:50 +01:00
params.c
pid.c
pid_namespace.c
profile.c
ptrace.c
range.c
reboot.c
kernel/reboot: emergency_restart: Set correct system_state
2023-11-28 16:50:19 +00:00
relay.c
relayfs: fix out-of-bounds access in relay_file_read
2023-05-17 11:35:58 +02:00
resource.c
rseq.c
seccomp.c
signal.c
smp.c
smpboot.c
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stop_machine.c
sys.c
getrusage: use sig->stats_lock rather than lock_task_sighand()
2024-03-15 10:48:19 -04:00
sys_ni.c
kernel/sys_ni: add compat entry for fadvise64_64
2022-09-05 10:27:38 +02:00
sysctl-test.c
sysctl.c
sched/rt: Disallow writing invalid values to sched_rt_period_us
2024-03-01 13:13:33 +01:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
up.c
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog_hld.c
watchdog/perf: more properly prevent false positives with turbo modes
2023-07-27 08:37:10 +02:00
workqueue.c
workqueue: Override implicit ordered attribute in workqueue_apply_unbound_cpumask()
2023-10-25 11:53:18 +02:00
workqueue_internal.h