Linux Kernel Selftest development
 help / color / mirror / Atom feed
From: Jan-Gerd Tenberge <janten@gmail.com>
To: bpf@vger.kernel.org
Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org,
	eddyz87@gmail.com, memxor@gmail.com, martin.lau@linux.dev,
	song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org,
	emil@etsalapatis.com, ihor.solodrai@linux.dev,
	john.fastabend@gmail.com, davem@davemloft.net,
	edumazet@kernel.org, kuba@kernel.org, pabeni@redhat.com,
	horms@kernel.org, jakub@cloudflare.com, jiayuan.chen@linux.dev,
	kuniyu@google.com, willemb@google.com, shuah@kernel.org,
	netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
	linux-kselftest@vger.kernel.org
Subject: [PATCH bpf 0/2] bpf: Fix iterator link update target validation
Date: Thu,  8 Oct 2026 18:13:07 +0200	[thread overview]
Message-ID: <20261008161309.8179-1-janten@gmail.com> (raw)

BPF iterator link creation validates constraints that depend on both the
program and the selected target. BPF_LINK_UPDATE only compares program
type, expected attach type, and attach BTF ID, allowing those checks to be
bypassed by attaching a compatible program first and replacing it later.

Runtime testing in disposable QEMU guests confirmed that the resulting
out-of-bounds access can reach kernel-owned metadata of a separately
allocated live map and cause a deterministic kernel panic. Corrupting a
victim map's refcount caused it to be freed while a verified BPF program
retained a reference. A same-size replacement reused the slab slot, and
the live program read the replacement's marker through its stale map
pointer. A separate test obtained a selected-address eight-byte kernel
read by changing the victim to another valid in-kernel operations table.
These tests did not demonstrate code execution or privilege escalation.
The UAF/read tests and the identity-boundary tests were separate; no single
combined exploit was demonstrated.

In a split-UID test, a UID-1001 process with CAP_BPF and CAP_PERFMON, but
neither CAP_SYS_ADMIN nor CAP_SYS_PTRACE, corrupted a UID-1000-owned map
without possessing its FD. BPF_MAP_GET_FD_BY_ID and pidfd_getfd both
returned EPERM. In another test, a child user namespace mapped to host UID
1000 and given an administrator-delegated BPF token triggered a host kernel
panic; tokenless tracing-program load returned EPERM. There is no
demonstrated default-unprivileged trigger.

Patch 1 reruns both target-specific validation and the iterator
sleepability check before replacing the link's program. Patch 2 covers
rejected array and socket-storage value accesses, a rejected sleepable
hash program, preservation of the old program after a failed update, and
a valid update.

The flaw was introduced by commit d6c4503cc296 ("bpf: Implement bpf
iterator for hash maps") and remains present in bpf.git at ff47652a4b66
and bpf-next at e1d84a37cba9. A patched ff47652a4b66-based kernel rejected
the invalid updates with -EACCES before the programs could execute.

Source reproducers, build-specific layout details, and exploitability logs
are available privately to maintainers on request. They are intentionally
not included in this public posting under the kernel's guidance for bugs
found with AI assistance. The public regression tests do not execute an
out-of-bounds access.

Testing performed:

  - Reproduced the bypass, cross-object metadata corruption, kernel panic,
    stale-reference reuse, and selected-address read on Debian Linux
    7.2.9+deb14-amd64 under isolated QEMU.
  - Built bpf_iter.o, map_iter.o, bpf_sk_storage.o, and sock_map.o with
    W=1.
  - Built the affected BPF selftest objects and skeletons with clang 19.
  - Compiled the bpf_iter host selftest with -Wall -Werror.
  - Passed git diff --check and checkpatch.pl --strict --no-signoff.
  - Verified that the series applies to bpf-next e1d84a37cba9.
  - Booted the patched ff47652a4b66-based kernel with vmlinux BTF under
    QEMU and confirmed that invalid updates return -EACCES.

An LLM assisted with discovery, analysis, fix implementation, test
development, and review.

Given the memory-safety impact and the Fixes tag, please consider patch 1
for applicable stable trees.

Jan-Gerd Tenberge (2):
  bpf: Revalidate iterator programs on link update
  selftests/bpf: Test iterator link target validation

 include/linux/bpf.h                           |  3 +
 kernel/bpf/bpf_iter.c                         | 15 +++++
 kernel/bpf/map_iter.c                         | 58 +++++++++++--------
 net/core/bpf_sk_storage.c                     | 24 +++++---
 net/core/sock_map.c                           | 26 ++++++---
 .../selftests/bpf/prog_tests/bpf_iter.c       | 34 ++++++++++-
 .../bpf/progs/bpf_iter_bpf_array_map.c        | 17 ++++++
 7 files changed, 136 insertions(+), 41 deletions(-)


base-commit: ff47652a4b66c067c765a7ad464d930b5a9367cc
-- 
2.54.0 (Apple Git-157)


             reply	other threads:[~2026-10-08 16:13 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 16:13 Jan-Gerd Tenberge [this message]
2026-10-08 16:13 ` [PATCH bpf 1/2] bpf: Revalidate iterator programs on link update Jan-Gerd Tenberge
2026-10-08 17:13   ` bot+bpf-ci
2026-10-08 16:13 ` [PATCH bpf 2/2] selftests/bpf: Test iterator link target validation Jan-Gerd Tenberge

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261008161309.8179-1-janten@gmail.com \
    --to=janten@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=davem@davemloft.net \
    --cc=eddyz87@gmail.com \
    --cc=edumazet@kernel.org \
    --cc=emil@etsalapatis.com \
    --cc=horms@kernel.org \
    --cc=ihor.solodrai@linux.dev \
    --cc=jakub@cloudflare.com \
    --cc=jiayuan.chen@linux.dev \
    --cc=john.fastabend@gmail.com \
    --cc=jolsa@kernel.org \
    --cc=kuba@kernel.org \
    --cc=kuniyu@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=martin.lau@linux.dev \
    --cc=memxor@gmail.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=shuah@kernel.org \
    --cc=song@kernel.org \
    --cc=willemb@google.com \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox