From: Ren Wei <weir@nebusec.ai>
To: bpf@vger.kernel.org, netdev@vger.kernel.org
Cc: daniel@iogearbox.net, john.fastabend@gmail.com, sdf@fomichev.me,
martin.lau@linux.dev, ast@kernel.org, andrii@kernel.org,
eddyz87@gmail.com, memxor@gmail.com, song@kernel.org,
yonghong.song@linux.dev, jolsa@kernel.org, emil@etsalapatis.com,
ihor.solodrai@linux.dev, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
horms@kernel.org, m.xhonneux@gmail.com, dlebrun@google.com,
vega@nebusec.ai, rakukuip@gmail.com, weir@nebusec.ai
Subject: [PATCH 1/1] bpf: fix TOCTOU in IPv6 SRH encapsulation
Date: Fri, 18 Sep 2026 00:33:51 +0800 [thread overview]
Message-ID: <20260917163408.252431-1-weir@nebusec.ai> (raw)
In-Reply-To: <cover.1789646866.git.rakukuip@gmail.com>
From: Luxiao Xu <rakukuip@gmail.com>
BPF helper SRH arguments may reference shared array-map values.
bpf_push_seg6_encap() validates the buffer using the constant
verifier-approved length, but target functions later reread hdrlen
and first_segment without snapshotting the validated bytes.
Another CPU or userspace can update the array-map value concurrently
between validation and use, changing hdrlen to request up to 2048 bytes
from a much smaller map allocation or changing the segment index.
The resulting memcpy and segment access can read beyond the map bounds,
potentially leaking adjacent kernel memory into transmitted packets or
triggering a kernel panic.
Fix this by duplicating the user-supplied SRH into a private buffer
with kmemdup() before validation and encapsulation, ensuring that
concurrent map updates cannot alter the header while in use, and
freeing the buffer on all return paths.
Fixes: fe94cc290f53 ("bpf: Add IPv6 Segment Routing helpers")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Assisted-by: LLM
Signed-off-by: Luxiao Xu <rakukuip@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
---
net/core/filter.c | 25 +++++++++++++++++--------
1 file changed, 17 insertions(+), 8 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 11bb0d236822..3587f4ba0511 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -6706,16 +6706,22 @@ static const struct bpf_func_proto bpf_xdp_check_mtu_proto = {
#if IS_ENABLED(CONFIG_IPV6_SEG6_BPF)
static int bpf_push_seg6_encap(struct sk_buff *skb, u32 type, void *hdr, u32 len)
{
- int err;
- struct ipv6_sr_hdr *srh = (struct ipv6_sr_hdr *)hdr;
+ struct ipv6_sr_hdr *srh;
+ int err = -EINVAL;
+
+ srh = kmemdup(hdr, len, GFP_ATOMIC);
+ if (!srh)
+ return -ENOMEM;
if (!seg6_validate_srh(srh, len, false))
- return -EINVAL;
+ goto out;
switch (type) {
case BPF_LWT_ENCAP_SEG6_INLINE:
- if (skb->protocol != htons(ETH_P_IPV6))
- return -EBADMSG;
+ if (skb->protocol != htons(ETH_P_IPV6)) {
+ err = -EBADMSG;
+ goto out;
+ }
err = seg6_do_srh_inline(skb, srh);
break;
@@ -6725,16 +6731,19 @@ static int bpf_push_seg6_encap(struct sk_buff *skb, u32 type, void *hdr, u32 len
err = seg6_do_srh_encap(skb, srh, IPPROTO_IPV6);
break;
default:
- return -EINVAL;
+ goto out;
}
bpf_compute_data_pointers(skb);
if (err)
- return err;
+ goto out;
skb_set_transport_header(skb, sizeof(struct ipv6hdr));
- return seg6_lookup_nexthop(skb, NULL, 0);
+ err = seg6_lookup_nexthop(skb, NULL, 0);
+out:
+ kfree(srh);
+ return err;
}
#endif /* CONFIG_IPV6_SEG6_BPF */
--
2.43.0
next prev parent reply other threads:[~2026-09-17 16:34 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 16:33 [PATCH 0/1] bpf: fix TOCTOU in IPv6 SRH encapsulation Ren Wei
2026-09-17 16:33 ` Ren Wei [this message]
2026-09-17 16:59 ` [PATCH 1/1] " Alexei Starovoitov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917163408.252431-1-weir@nebusec.ai \
--to=weir@nebusec.ai \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=dlebrun@google.com \
--cc=eddyz87@gmail.com \
--cc=edumazet@google.com \
--cc=emil@etsalapatis.com \
--cc=horms@kernel.org \
--cc=ihor.solodrai@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=kuba@kernel.org \
--cc=m.xhonneux@gmail.com \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=rakukuip@gmail.com \
--cc=sdf@fomichev.me \
--cc=song@kernel.org \
--cc=vega@nebusec.ai \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox