netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] Fixes the null pointer deferences in nsim_bpf
@ 2023-11-10  8:44 Dipendra Khadka
  2023-11-10  8:52 ` Eric Dumazet
  2023-11-10 11:18 ` [PATCH v2] " Dipendra Khadka
  0 siblings, 2 replies; 5+ messages in thread
From: Dipendra Khadka @ 2023-11-10  8:44 UTC (permalink / raw)
  To: kuba, davem, edumazet, pabeni
  Cc: Dipendra Khadka, netdev, linux-kernel, linux-kernel-mentees,
	syzbot+44c2416196b7c607f226

Syzkaller found a null pointer dereference in nsim_bpf
originating from the lack of a null check for state.

This patch fixes the issue by adding a check for state
in two functions nsim_prog_set_loaded and nsim_setup_prog_hw_checks

Reported-by: syzbot+44c2416196b7c607f226@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com./bug?extid=44c2416196b7c607f226

Signed-off-by: Dipendra Khadka <kdipendra88@gmail.com>
---
 drivers/net/netdevsim/bpf.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/drivers/net/netdevsim/bpf.c b/drivers/net/netdevsim/bpf.c
index f60eb97e3a62..e407efb0e3de 100644
--- a/drivers/net/netdevsim/bpf.c
+++ b/drivers/net/netdevsim/bpf.c
@@ -97,7 +97,8 @@ static void nsim_prog_set_loaded(struct bpf_prog *prog, bool loaded)
 		return;
 
 	state = prog->aux->offload->dev_priv;
-	state->is_loaded = loaded;
+	if (state)
+		state->is_loaded = loaded;
 }
 
 static int
@@ -317,10 +318,12 @@ nsim_setup_prog_hw_checks(struct netdevsim *ns, struct netdev_bpf *bpf)
 	}
 
 	state = bpf->prog->aux->offload->dev_priv;
-	if (WARN_ON(strcmp(state->state, "xlated"))) {
-		NSIM_EA(bpf->extack, "offloading program in bad state");
-		return -EINVAL;
-	}
+	if (state) {
+		if (WARN_ON(strcmp(state->state, "xlated"))) {
+			NSIM_EA(bpf->extack, "offloading program in bad state");
+			return -EINVAL;
+		}
+	}
 	return 0;
 }
 
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2023-11-10 19:20 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-11-10  8:44 [PATCH] Fixes the null pointer deferences in nsim_bpf Dipendra Khadka
2023-11-10  8:52 ` Eric Dumazet
2023-11-10 11:18 ` [PATCH v2] " Dipendra Khadka
2023-11-10 19:12   ` Jakub Kicinski
2023-11-10 19:20     ` Stanislav Fomichev

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).