From mboxrd@z Thu Jan 1 00:00:00 1970 From: Dan Carpenter Subject: [PATCH 1/2] samples: bpf: ensure that we don't load over MAX_PROGS programs Date: Fri, 13 Jul 2018 18:11:39 +0300 Message-ID: <20180713151139.aiqginrahbimfsop@kili.mountain> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: Daniel Borkmann , netdev@vger.kernel.org, kernel-janitors@vger.kernel.org To: Alexei Starovoitov Return-path: Received: from aserp2120.oracle.com ([141.146.126.78]:48538 "EHLO aserp2120.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729643AbeGMP1R (ORCPT ); Fri, 13 Jul 2018 11:27:17 -0400 Content-Disposition: inline Sender: netdev-owner@vger.kernel.org List-ID: I can't see that we check prog_cnt to ensure it doesn't go over MAX_PROGS. Signed-off-by: Dan Carpenter diff --git a/samples/bpf/bpf_load.c b/samples/bpf/bpf_load.c index 89161c9ed466..904e775d1a44 100644 --- a/samples/bpf/bpf_load.c +++ b/samples/bpf/bpf_load.c @@ -107,6 +107,9 @@ static int load_and_attach(const char *event, struct bpf_insn *prog, int size) return -1; } + if (prog_cnt == MAX_PROGS) + return -1; + fd = bpf_load_program(prog_type, prog, insns_cnt, license, kern_version, bpf_log_buf, BPF_LOG_BUF_SIZE); if (fd < 0) {