* [PATCH bpf v2] bpf: Fix NULL pointer dereference in bpf_sock_from_file
@ 2026-08-20 15:25 Syeda Mahnur Asif
0 siblings, 0 replies; only message in thread
From: Syeda Mahnur Asif @ 2026-08-20 15:25 UTC (permalink / raw)
To: bpf, ast, daniel; +Cc: netdev, andrii, Syeda Mahnur Asif, Emil Tsalapatis
bpf_sock_from_file should not dereference a NULL file pointer.
KASAN detects a null-ptr-deref when eBPF tracing
fentry/fexit programs are attached to points such as
__mmap_region and file_map_prot_check kernel functions. This can
result in a NULL file pointer flowing from context to the helper.
A minimal check before dereferencing can fix this.
Fixes: b60da4955f53 ("bpf: Only provide bpf_sock_from_file with CONFIG_NET")
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Syeda Mahnur Asif <s.mahnur.a@gmail.com>
---
v2:
- Added Reviewed-by from Emil Tsalapatis
- Fixed name in Signed-off-by
net/core/filter.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 16845987b244..7c3caae4bafc 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -12182,7 +12182,10 @@ const struct bpf_func_proto bpf_skc_to_mptcp_sock_proto = {
BPF_CALL_1(bpf_sock_from_file, struct file *, file)
{
- return (unsigned long)sock_from_file(file);
+ if (file)
+ return (unsigned long)sock_from_file(file);
+
+ return (unsigned long)NULL;
}
BTF_ID_LIST(bpf_sock_from_file_btf_ids)
--
2.53.0
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-20 15:25 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-20 15:25 [PATCH bpf v2] bpf: Fix NULL pointer dereference in bpf_sock_from_file Syeda Mahnur Asif
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox