BPF List
 help / color / mirror / Atom feed
From: Emil Tsalapatis <emil@etsalapatis.com>
To: bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, eddyz87@gmail.com,
	memxor@gmail.com, daniel@iogearbox.net, netdev@vger.kernel.org,
	Emil Tsalapatis <emil@etsalapatis.com>,
	Nicholas Carlini <nicholas@carlini.com>
Subject: [PATCH bpf 01/11] bpf: Fix bounds check for skb-backed dynptrs
Date: Wed, 16 Sep 2026 05:08:19 +0000	[thread overview]
Message-ID: <20260916050830.8774-2-emil@etsalapatis.com> (raw)
In-Reply-To: <20260916050830.8774-1-emil@etsalapatis.com>

The skb_pointer_if_linear() function checks whether a
memory region of length len starting at offset off into
the skb is in the linear area, and returns a pointer to
the region if so. The check currently subtracts between
skb_headlen and offset of the check, and since skb_headlen
is unsigned the subtraction can underflow. This causes the
bounds check to spuriously pass and generate an arbitrary
pointer of the form *(skb->data + off).

The only user of this helper is currently skb-backed BPF
dynptr code. Returning the wrong pointer leads to the
dynptr erroneously being backed with invalid memory.

Ensure the subtraction cannot underflow, and fail the check if
it would. Use u64 arithmetic to also prevent overflow when
calculating (skb_headlen(skb) - off) since off is unsigned.

Fixes: 6f5a630d7c57 ("bpf, net: Introduce skb_pointer_if_linear().")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
---

While the code for this is in skbuff.h, the only consumer is
BPF-related, as is the selftest that validates it in the next
patch. So I think it makes sense to route through BPF. If there
are any objections I will split the patch off and resend to net.

 include/linux/skbuff.h | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 421f6fc45..d0c1463db 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -4372,7 +4372,8 @@ skb_header_pointer_careful(const struct sk_buff *skb, int offset,
 static inline void * __must_check
 skb_pointer_if_linear(const struct sk_buff *skb, int offset, int len)
 {
-	if (likely(skb_headlen(skb) - offset >= len))
+	if (likely((u64)offset <= skb_headlen(skb) && 
+			(u64)len <= skb_headlen(skb) - (u64)offset))
 		return skb->data + offset;
 	return NULL;
 }
-- 
2.54.0


  reply	other threads:[~2026-09-16  5:08 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-16  5:08 [PATCH bpf 00/11] skb/arena bugfixes Emil Tsalapatis
2026-09-16  5:08 ` Emil Tsalapatis [this message]
2026-09-16 11:52   ` [PATCH bpf 01/11] bpf: Fix bounds check for skb-backed dynptrs Jiayuan Chen
2026-09-16 23:08   ` Jakub Kicinski
2026-09-16  5:08 ` [PATCH bpf 02/11] selftests/bpf: Test dynptr slices past end of skb Emil Tsalapatis
2026-09-16  5:18   ` sashiko-bot
2026-09-16  5:08 ` [PATCH bpf 03/11] bpf: Fix bpf_sock context code generation Emil Tsalapatis
2026-09-16 12:21   ` Jiayuan Chen
2026-09-16  5:08 ` [PATCH bpf 04/11] selftests/bpf: Add selftests for rx_queue_mapping context access Emil Tsalapatis
2026-09-16  5:08 ` [PATCH bpf 05/11] bpf: Reject pkt arguments in mutating subprogs Emil Tsalapatis
2026-09-16  5:57   ` Amery Hung
2026-09-16  5:58     ` Amery Hung
2026-09-16 18:41     ` Emil Tsalapatis
2026-09-16 19:26       ` Amery Hung
2026-09-16  5:08 ` [PATCH bpf 06/11] selftests/bpf: Test rejection of pkt args to " Emil Tsalapatis
2026-09-16  5:08 ` [PATCH bpf 07/11] bpf: Prevent variable arena/non-arena register contents Emil Tsalapatis
2026-09-16  5:08 ` [PATCH bpf 08/11] selftests/bpf: Test for mixed arena/nonarena code paths Emil Tsalapatis
2026-09-16  5:17   ` sashiko-bot
2026-09-16  5:08 ` [PATCH bpf 09/11] bpf: Track whether dynptr type is known Emil Tsalapatis
2026-09-16  5:22   ` sashiko-bot
2026-09-16 18:41     ` Emil Tsalapatis
2026-09-16  5:08 ` [PATCH bpf 10/11] bpf: Track skb memory invalidation by packet-backed dynptrs Emil Tsalapatis
2026-09-16  5:08 ` [PATCH bpf 11/11] selftests/bpf: Test dynptr slice invalidation on skb clobber Emil Tsalapatis

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260916050830.8774-2-emil@etsalapatis.com \
    --to=emil@etsalapatis.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=memxor@gmail.com \
    --cc=netdev@vger.kernel.org \
    --cc=nicholas@carlini.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox