Thread (2 messages) 2 messages, 2 authors, 2024-12-10

Re: [PATCH] bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors

From: patchwork-bot+netdevbpf@kernel.org
Date: 2024-12-10 18:30:16
Also in: bpf, lkml, stable

Hello:

This patch was applied to bpf/bpf.git (master)
by Andrii Nakryiko [off-list ref]:

On Tue, 10 Dec 2024 17:32:13 +0100 you wrote:
Uprobes always use bpf_prog_run_array_uprobe() under tasks-trace-RCU
protection. But it is possible to attach a non-sleepable BPF program to a
uprobe, and non-sleepable BPF programs are freed via normal RCU (see
__bpf_prog_put_noref()). This leads to UAF of the bpf_prog because a normal
RCU grace period does not imply a tasks-trace-RCU grace period.

Fix it by explicitly waiting for a tasks-trace-RCU grace period after
removing the attachment of a bpf_prog to a perf_event.

[...]
Here is the summary with links:
  - bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors
    https://git.kernel.org/bpf/bpf/c/ef1b808e3b7c

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help