From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DE367218EB1; Mon, 27 Oct 2025 18:39:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1761590394; cv=none; b=f/3nXjeG8KQ0XQN823jREir6xpbfG8FOaO4mtZ+EnH7OefioxpvtdZygfAaDZRaRff2/UTmRIXK1pu9pXkCnFFH9QEs3L0YDmsJzmNPsHPYX9t2fQNirWWURytRThOluVXzI72j0bDusxTlcfsL2K2SwzELjbLvSPeSXGlQW5WQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1761590394; c=relaxed/simple; bh=SQUzB8EoNnmeweFdYTvktuG2DdDAcG0rNCQ0q/Gdi5U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GzVgw+36B9eQuFPG69xM76UeIhFerqBq2VpYyyP+dPY8Q9oMPU0EXIL6LUj8aGnCkurGGpxol7Eet9XwJO4viiJJBhiZUMb/exRAPAUPc2uuziL3rli4yGeeF5PxoZxuEszUczJxxZyGJ/XZ6kGnr+V7UmupVzMwO4TtJpPt3mY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Y+ooWAHK; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Y+ooWAHK" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6EC68C4CEF1; Mon, 27 Oct 2025 18:39:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1761590393; bh=SQUzB8EoNnmeweFdYTvktuG2DdDAcG0rNCQ0q/Gdi5U=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=Y+ooWAHKqzxPGrXgc7q3dSC41J6wRIXMCOgS+NlrpUaAWi32pnawSyFeCEQbiVtcG PSlx7O3Yeg/25kAF783y7ZrtZ5mr18QILbkr1YqVoP5vyqkkNlXHVSUAsz3RLNjB7x 3vbxftORq1W+DDoV84Ml/w10MtNP0+4aDlsCmm/0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, syzbot+136ca59d411f92e821b7@syzkaller.appspotmail.com, Paul Chaignon , Daniel Borkmann , Eduard Zingerman , Sasha Levin Subject: [PATCH 5.4 028/224] bpf: Explicitly check accesses to bpf_sock_addr Date: Mon, 27 Oct 2025 19:32:54 +0100 Message-ID: <20251027183509.759350020@linuxfoundation.org> X-Mailer: git-send-email 2.51.1 In-Reply-To: <20251027183508.963233542@linuxfoundation.org> References: <20251027183508.963233542@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.4-stable review patch. If anyone has any objections, please let me know. ------------------ From: Paul Chaignon [ Upstream commit 6fabca2fc94d33cdf7ec102058983b086293395f ] Syzkaller found a kernel warning on the following sock_addr program: 0: r0 = 0 1: r2 = *(u32 *)(r1 +60) 2: exit which triggers: verifier bug: error during ctx access conversion (0) This is happening because offset 60 in bpf_sock_addr corresponds to an implicit padding of 4 bytes, right after msg_src_ip4. Access to this padding isn't rejected in sock_addr_is_valid_access and it thus later fails to convert the access. This patch fixes it by explicitly checking the various fields of bpf_sock_addr in sock_addr_is_valid_access. I checked the other ctx structures and is_valid_access functions and didn't find any other similar cases. Other cases of (properly handled) padding are covered in new tests in a subsequent patch. Fixes: 1cedee13d25a ("bpf: Hooks for sys_sendmsg") Reported-by: syzbot+136ca59d411f92e821b7@syzkaller.appspotmail.com Signed-off-by: Paul Chaignon Signed-off-by: Daniel Borkmann Acked-by: Eduard Zingerman Acked-by: Daniel Borkmann Closes: https://syzkaller.appspot.com/bug?extid=136ca59d411f92e821b7 Link: https://lore.kernel.org/bpf/b58609d9490649e76e584b0361da0abd3c2c1779.1758094761.git.paul.chaignon@gmail.com Signed-off-by: Sasha Levin --- net/core/filter.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/net/core/filter.c b/net/core/filter.c index fd18497977bdf..2c56c910a0c13 100644 --- a/net/core/filter.c +++ b/net/core/filter.c @@ -7132,13 +7132,17 @@ static bool sock_addr_is_valid_access(int off, int size, return false; info->reg_type = PTR_TO_SOCKET; break; - default: - if (type == BPF_READ) { - if (size != size_default) - return false; - } else { + case bpf_ctx_range(struct bpf_sock_addr, user_family): + case bpf_ctx_range(struct bpf_sock_addr, family): + case bpf_ctx_range(struct bpf_sock_addr, type): + case bpf_ctx_range(struct bpf_sock_addr, protocol): + if (type != BPF_READ) return false; - } + if (size != size_default) + return false; + break; + default: + return false; } return true; -- 2.51.0