All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH bpf v2] bpf: Fix NULL pointer dereference in __bpf_sk_storage_map_seq_show
@ 2026-09-11 14:03 Cen Zhang (Microsoft Security FORGE Labs)
  2026-09-11 14:24 ` luoxuanqiang
  2026-09-11 14:28 ` sashiko-bot
  0 siblings, 2 replies; 4+ messages in thread
From: Cen Zhang (Microsoft Security FORGE Labs) @ 2026-09-11 14:03 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Martin KaFai Lau
  Cc: Amery Hung, Xuanqiang Luo, David S. Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Simon Horman, Fushuai Wang,
	Weiming Shi, Matt Bobrowski, Kees Cook, Menglong Dong, bpf,
	netdev, linux-kernel, AutonomousCodeSecurity, xmei5, tgopinath,
	kys

Iterating a sk_storage map is a two-stage operation:
bpf_sk_storage_map_seq_find_next() returns a selem, then
__bpf_sk_storage_map_seq_show() uses it. The latter re-reads
selem->local_storage via rcu_dereference() without checking for NULL.
A concurrent socket close can unlink the selem and clear that pointer
between the two stages, causing a NULL dereference of sk_storage->owner.

Oops: general protection fault, probably for non-canonical
   address 0xdffffc0000000011
  net/core/bpf_sk_storage.c:809 __bpf_sk_storage_map_seq_show()
  bpf_seq_read+0x366/0x1120
  vfs_read+0x174/0xa50
  ksys_read+0xfc/0x1d0

Return SEQ_SKIP if the re-read yields NULL. This prevents the dereference
and tells bpf_seq_read() that the stale element was skipped, so it does
not consume an iterator sequence number without running the BPF program.

Fixes: 0be08389c7f2 ("bpf: Switch to bpf_selem_unlink_nofail in bpf_local_storage_{map_free, destroy}")
Reported-by: Xiang Mei (Microsoft) <xmei5@asu.edu>
Closes: https://lore.kernel.org/all/20260827051859.45511-1-blbllhy@gmail.com/
Suggested-by: Amery Hung <ameryhung@gmail.com>
Suggested-by: Xuanqiang Luo <xuanqiang.luo@linux.dev>
Link: https://lore.kernel.org/all/CAMB2axNFOC9G2RwOCnsWDth83REMWnmPE8gxMwbLYoGusw9miA@mail.gmail.com/
Link: https://lore.kernel.org/all/c3f2a61d-d5bc-454c-987d-717b5f8c8809@linux.dev/
Cc: AutonomousCodeSecurity@microsoft.com
Signed-off-by: Cen Zhang (Microsoft Security FORGE Labs) <cenzhang@linux.microsoft.com>
Assisted-by: Copilot (Grok 4.6)
---
Changes in v2:
- Return SEQ_SKIP instead of 0 when the storage disappeared, preserving
  the iterator sequence number for the next valid element.
- Correct the Fixes tag to the commit that switched the destruction path
  to bpf_selem_unlink_nofail().
- Rebase onto the current bpf master branch.

 net/core/bpf_sk_storage.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/core/bpf_sk_storage.c b/net/core/bpf_sk_storage.c
index 1d295a8769fa..7d02245aa704 100644
--- a/net/core/bpf_sk_storage.c
+++ b/net/core/bpf_sk_storage.c
@@ -806,6 +806,8 @@ static int __bpf_sk_storage_map_seq_show(struct seq_file *seq,
 		ctx.map = info->map;
 		if (selem) {
 			sk_storage = rcu_dereference(selem->local_storage);
+			if (!sk_storage)
+				return SEQ_SKIP;
 			ctx.sk = sk_storage->owner;
 			ctx.value = SDATA(selem)->data;
 		}

base-commit: 15071f2a1263e82150c77eeb1e94dbfc31950a8e
-- 
2.55.0

^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-11 15:34 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 14:03 [PATCH bpf v2] bpf: Fix NULL pointer dereference in __bpf_sk_storage_map_seq_show Cen Zhang (Microsoft Security FORGE Labs)
2026-09-11 14:24 ` luoxuanqiang
2026-09-11 14:28 ` sashiko-bot
2026-09-11 15:34   ` Cen Zhang (Microsoft Security FORGE Labs)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.