From: sashiko-bot@kernel.org
To: "Emil Tsalapatis" <emil@etsalapatis.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf v2 01/11] bpf: Fix bounds check for skb-backed dynptrs
Date: Tue, 22 Sep 2026 17:27:11 +0000 [thread overview]
Message-ID: <20260922172712.0F9851F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260922172028.6269-2-emil@etsalapatis.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf: commit message claims u64 arithmetic but uses 32-bit unsigned
--
commit 5861693b35f3cce5042bdc052c43183ecc29425f
Author: Emil Tsalapatis <emil@etsalapatis.com>
bpf: Fix bounds check for skb-backed dynptrs
This commit fixes an underflow vulnerability in the bounds check for
skb-backed dynptrs within skb_pointer_if_linear(). It prevents spurious
passes by converting offsets and lengths to unsigned integers before
performing bounds comparisons.
> diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
> index 421f6fc454511..c8e21903074c3 100644
> --- a/include/linux/skbuff.h
> +++ b/include/linux/skbuff.h
> @@ -4372,7 +4372,10 @@ skb_header_pointer_careful(const struct sk_buff *skb, int offset,
> static inline void * __must_check
> skb_pointer_if_linear(const struct sk_buff *skb, int offset, int len)
> {
> - if (likely(skb_headlen(skb) - offset >= len))
> + unsigned int uoffset = (unsigned int)offset;
> +
> + if (likely(uoffset <= skb_headlen(skb) &&
> + (unsigned int)len <= skb_headlen(skb) - uoffset))
[Severity: Medium]
The commit message explicitly states "Use u64 arithmetic to also prevent
overflow when calculating (skb_headlen(skb) - off)", but this implementation
strictly uses 32-bit unsigned arithmetic.
Since the 32-bit unsigned math appears to correctly prevent the underflow and
overflow in this context, is the commit message's reference to u64 arithmetic
inaccurate? Does the commit message need to be updated to match the
unsigned int implementation here?
> return skb->data + offset;
> return NULL;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922172028.6269-1-emil@etsalapatis.com?part=1
next prev parent reply other threads:[~2026-09-22 17:27 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 17:20 [PATCH bpf v2 00/11] skb/arena bugfixes Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 01/11] bpf: Fix bounds check for skb-backed dynptrs Emil Tsalapatis
2026-09-22 17:27 ` sashiko-bot [this message]
2026-09-22 20:15 ` Amery Hung
2026-09-22 17:20 ` [PATCH bpf v2 02/11] selftests/bpf: Test dynptr slices past end of skb Emil Tsalapatis
2026-09-22 17:28 ` sashiko-bot
2026-09-22 20:16 ` Amery Hung
2026-09-22 17:20 ` [PATCH bpf v2 03/11] bpf: Fix bpf_sock context code generation Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 04/11] selftests/bpf: Add selftests for rx_queue_mapping context access Emil Tsalapatis
2026-09-22 17:36 ` sashiko-bot
2026-09-22 17:20 ` [PATCH bpf v2 05/11] bpf: Reject pkt arguments in mutating subprogs Emil Tsalapatis
2026-09-22 20:32 ` Amery Hung
2026-09-22 17:20 ` [PATCH bpf v2 06/11] selftests/bpf: Test rejection of pkt args to " Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 07/11] bpf: Prevent variable arena/non-arena register contents Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 08/11] selftests/bpf: Test for mixed arena/nonarena code paths Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 09/11] bpf: Track whether dynptr type is known Emil Tsalapatis
2026-09-22 18:46 ` Alexei Starovoitov
2026-09-22 20:23 ` Amery Hung
2026-09-22 20:28 ` Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 10/11] bpf: Track skb memory invalidation by packet-backed dynptrs Emil Tsalapatis
2026-09-22 20:06 ` Amery Hung
2026-09-22 20:29 ` Emil Tsalapatis
2026-09-22 17:20 ` [PATCH bpf v2 11/11] selftests/bpf: Test dynptr slice invalidation on skb clobber Emil Tsalapatis
2026-09-22 19:40 ` [PATCH bpf v2 00/11] skb/arena bugfixes patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922172712.0F9851F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=emil@etsalapatis.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox