public inbox for linux-arm-kernel@lists.infradead.org
 help / color / mirror / Atom feed
* [PATCH] arm64: bpf: Fix UBSAN misaligned access in BPF JIT
@ 2026-02-24  9:29 Fuad Tabba
  2026-02-24 22:11 ` Will Deacon
  0 siblings, 1 reply; 12+ messages in thread
From: Fuad Tabba @ 2026-02-24  9:29 UTC (permalink / raw)
  To: bpf, linux-arm-kernel, linux-kernel; +Cc: tabba

struct bpf_plt contains a u64 'target' field. The BPF JIT allocator
was using an alignment of 4 bytes (sizeof(u32)), which could lead
to the 'target' field being misaligned in the JIT buffer.

Increase the alignment requirement to 8 bytes (sizeof(u64)) in
bpf_jit_binary_pack_alloc() to guarantee proper alignment for
struct bpf_plt.

Fixes: b2ad54e1533e9 ("bpf, arm64: Implement bpf_arch_text_poke() for arm64")
Signed-off-by: Fuad Tabba <tabba@google.com>
---
 arch/arm64/net/bpf_jit_comp.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
index 356d33c7a4ae..adf84962d579 100644
--- a/arch/arm64/net/bpf_jit_comp.c
+++ b/arch/arm64/net/bpf_jit_comp.c
@@ -2119,7 +2119,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_prog *prog)
 	extable_offset = round_up(prog_size + PLT_TARGET_SIZE, extable_align);
 	image_size = extable_offset + extable_size;
 	ro_header = bpf_jit_binary_pack_alloc(image_size, &ro_image_ptr,
-					      sizeof(u32), &header, &image_ptr,
+					      sizeof(u64), &header, &image_ptr,
 					      jit_fill_hole);
 	if (!ro_header) {
 		prog = orig_prog;
-- 
2.53.0.371.g1d285c8824-goog



^ permalink raw reply related	[flat|nested] 12+ messages in thread
* [PATCH] arm64: bpf: Fix UBSAN misaligned access in BPF JIT
@ 2026-02-24  9:31 Fuad Tabba
  2026-02-25  1:43 ` Xu Kuohai
  0 siblings, 1 reply; 12+ messages in thread
From: Fuad Tabba @ 2026-02-24  9:31 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Puranjay Mohan, Catalin Marinas, Will Deacon, bpf,
	linux-arm-kernel, linux-kernel
  Cc: Martin KaFai Lau, Eduard Zingerman, Song Liu, Yonghong Song,
	John Fastabend, KP Singh, Stanislav Fomichev, Hao Luo, Jiri Olsa,
	Xu Kuohai, Jakub Sitnicki, Jean-Philippe Brucker, tabba

struct bpf_plt contains a u64 'target' field. The BPF JIT allocator
was using an alignment of 4 bytes (sizeof(u32)), which could lead
to the 'target' field being misaligned in the JIT buffer.

Increase the alignment requirement to 8 bytes (sizeof(u64)) in
bpf_jit_binary_pack_alloc() to guarantee proper alignment for
struct bpf_plt.

Fixes: b2ad54e1533e9 ("bpf, arm64: Implement bpf_arch_text_poke() for arm64")
Signed-off-by: Fuad Tabba <tabba@google.com>
---
 arch/arm64/net/bpf_jit_comp.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
index 356d33c7a4ae..adf84962d579 100644
--- a/arch/arm64/net/bpf_jit_comp.c
+++ b/arch/arm64/net/bpf_jit_comp.c
@@ -2119,7 +2119,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_prog *prog)
 	extable_offset = round_up(prog_size + PLT_TARGET_SIZE, extable_align);
 	image_size = extable_offset + extable_size;
 	ro_header = bpf_jit_binary_pack_alloc(image_size, &ro_image_ptr,
-					      sizeof(u32), &header, &image_ptr,
+					      sizeof(u64), &header, &image_ptr,
 					      jit_fill_hole);
 	if (!ro_header) {
 		prog = orig_prog;
-- 
2.53.0.371.g1d285c8824-goog



^ permalink raw reply related	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-02-26  1:34 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-02-24  9:29 [PATCH] arm64: bpf: Fix UBSAN misaligned access in BPF JIT Fuad Tabba
2026-02-24 22:11 ` Will Deacon
2026-02-25  9:07   ` Fuad Tabba
  -- strict thread matches above, loose matches on Subject: below --
2026-02-24  9:31 Fuad Tabba
2026-02-25  1:43 ` Xu Kuohai
2026-02-25  9:08   ` Fuad Tabba
2026-02-25  9:46     ` Xu Kuohai
2026-02-25 11:00       ` Fuad Tabba
2026-02-26  1:34         ` Xu Kuohai
2026-02-25 17:47       ` Will Deacon
2026-02-25 17:53         ` Fuad Tabba
2026-02-25 18:22           ` Will Deacon

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox