From: "Emil Tsalapatis" <emil@etsalapatis.com>
To: "Jiri Olsa" <jolsa@kernel.org>,
"Alexei Starovoitov" <ast@kernel.org>,
"Daniel Borkmann" <daniel@iogearbox.net>,
"Andrii Nakryiko" <andrii@kernel.org>
Cc: <stable@vger.kernel.org>, "Sashiko" <sashiko-bot@kernel.org>,
<bpf@vger.kernel.org>, "Martin KaFai Lau" <martin.lau@linux.dev>,
"Eduard Zingerman" <eddyz87@gmail.com>,
"Song Liu" <songliubraving@fb.com>, "Yonghong Song" <yhs@fb.com>
Subject: Re: [PATCH bpf] bpf: Add missing access_ok call to copy_user_syms
Date: Tue, 16 Jun 2026 19:35:32 -0400 [thread overview]
Message-ID: <DJAV95U1GCBI.1LKNKIW9SW740@etsalapatis.com> (raw)
In-Reply-To: <20260616083056.405652-1-jolsa@kernel.org>
On Tue Jun 16, 2026 at 4:30 AM EDT, Jiri Olsa wrote:
> As reported by sashiko we use __get_user without prior access_ok call on the
> user space pointer. Adding the missing call for the whole pointer array.
>
> Plus removing the err check in the error path, because it's not needed and
> also we can return -ENOMEM directly from the first kvmalloc_array fail path.
>
> Cc: stable@vger.kernel.org
> [1] https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.kernel.org/
> Fixes: 0236fec57a15 ("bpf: Resolve symbols with ftrace_lookup_symbols for kprobe multi link")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.kernel.org/
> Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
> ---
> kernel/trace/bpf_trace.c | 11 ++++++-----
> 1 file changed, 6 insertions(+), 5 deletions(-)
>
> diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
> index 82f8feea6931..75495a5c3507 100644
> --- a/kernel/trace/bpf_trace.c
> +++ b/kernel/trace/bpf_trace.c
> @@ -2376,9 +2376,12 @@ static int copy_user_syms(struct user_syms *us, unsigned long __user *usyms, u32
> int err = -ENOMEM;
> unsigned int i;
>
> + if (!access_ok(usyms, cnt * sizeof(*usyms)))
> + return -EFAULT;
> +
> syms = kvmalloc_array(cnt, sizeof(*syms), GFP_KERNEL);
> if (!syms)
> - goto error;
> + return -ENOMEM;
>
> buf = kvmalloc_array(cnt, KSYM_NAME_LEN, GFP_KERNEL);
> if (!buf)
> @@ -2403,10 +2406,8 @@ static int copy_user_syms(struct user_syms *us, unsigned long __user *usyms, u32
> return 0;
>
> error:
> - if (err) {
> - kvfree(syms);
> - kvfree(buf);
> - }
> + kvfree(syms);
> + kvfree(buf);
> return err;
> }
>
prev parent reply other threads:[~2026-06-16 23:35 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-16 8:30 [PATCH bpf] bpf: Add missing access_ok call to copy_user_syms Jiri Olsa
2026-06-16 8:42 ` sashiko-bot
2026-06-16 10:01 ` Jiri Olsa
2026-06-16 23:35 ` Emil Tsalapatis [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DJAV95U1GCBI.1LKNKIW9SW740@etsalapatis.com \
--to=emil@etsalapatis.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=jolsa@kernel.org \
--cc=martin.lau@linux.dev \
--cc=sashiko-bot@kernel.org \
--cc=songliubraving@fb.com \
--cc=stable@vger.kernel.org \
--cc=yhs@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.