Thread (30 messages) flat view 30 messages, 6 authors, 2015-10-08

Re: [PATCH net-next 1/2] bpf: enable non-root eBPF programs

From: Ingo Molnar <hidden>
Date: 2015-10-06 07:13:56
Also in: lkml, netdev

* Alexei Starovoitov [off-list ref] wrote:
On 10/5/15 3:14 PM, Daniel Borkmann wrote:
quoted
One scenario that comes to mind ... what happens when there are kernel
pointers stored in skb->cb[] (either from the current layer or an old
one from a different layer that the skb went through previously, but
which did not get overwritten)?

Socket filters could read a portion of skb->cb[] also when unprived and
leak that out through maps. I think the verifier doesn't catch that,
right?
grrr. indeed. previous layer before sk_filter() can leave junk in there.
Could this be solved by activating zeroing/sanitizing of this data if there's an 
active BPF function around that can access that socket?

Thanks,

	Ingo
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help