Syzkaller found a null pointer dereference in nsim_bpf
originating from the lack of a null check for state.
This patch fixes the issue by adding a check for state
in two functions nsim_prog_set_loaded and nsim_setup_prog_hw_checks
Reported-by: syzbot+44c2416196b7c607f226@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com./bug?extid=44c2416196b7c607f226
Signed-off-by: Dipendra Khadka <redacted>
---
drivers/net/netdevsim/bpf.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
@@ -317,10 +318,12 @@ nsim_setup_prog_hw_checks(struct netdevsim *ns, struct netdev_bpf *bpf)}state=bpf->prog->aux->offload->dev_priv;-if(WARN_ON(strcmp(state->state,"xlated"))){-NSIM_EA(bpf->extack,"offloading program in bad state");-return-EINVAL;-}+if(state){+if(WARN_ON(strcmp(state->state,"xlated"))){+NSIM_EA(bpf->extack,"offloading program in bad state");+return-EINVAL;+}+}return0;}
Syzkaller found a null pointer dereference in nsim_bpf
originating from the lack of a null check for state.
This patch fixes the issue by adding a check for state
in two functions nsim_prog_set_loaded() and nsim_setup_prog_hw_checks()
Reported-by: syzbot+44c2416196b7c607f226@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com./bug?extid=44c2416196b7c607f226
Fixes: 31d3ad832948 ("netdevsim: add bpf offload support")
Signed-off-by: Dipendra Khadka <redacted>
---
drivers/net/netdevsim/bpf.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
@@ -317,9 +318,11 @@ nsim_setup_prog_hw_checks(struct netdevsim *ns, struct netdev_bpf *bpf)}state=bpf->prog->aux->offload->dev_priv;-if(WARN_ON(strcmp(state->state,"xlated"))){-NSIM_EA(bpf->extack,"offloading program in bad state");-return-EINVAL;+if(state){+if(WARN_ON(strcmp(state->state,"xlated"))){+NSIM_EA(bpf->extack,"offloading program in bad state");+return-EINVAL;+}}return0;}
From: Eric Dumazet <edumazet@google.com> Date: 2023-11-10 17:57:10
On Fri, Nov 10, 2023 at 9:45 AM Dipendra Khadka [off-list ref] wrote:
Syzkaller found a null pointer dereference in nsim_bpf
originating from the lack of a null check for state.
This patch fixes the issue by adding a check for state
in two functions nsim_prog_set_loaded and nsim_setup_prog_hw_checks
Reported-by: syzbot+44c2416196b7c607f226@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com./bug?extid=44c2416196b7c607f226
Please add a Fixes: tag, and remove this empty line, thanks.
@@ -317,10 +318,12 @@ nsim_setup_prog_hw_checks(struct netdevsim *ns, struct netdev_bpf *bpf)}state=bpf->prog->aux->offload->dev_priv;-if(WARN_ON(strcmp(state->state,"xlated"))){-NSIM_EA(bpf->extack,"offloading program in bad state");-return-EINVAL;-}+if(state){+if(WARN_ON(strcmp(state->state,"xlated"))){+NSIM_EA(bpf->extack,"offloading program in bad state");+return-EINVAL;+}+}return0;}--
From: Jakub Kicinski <kuba@kernel.org> Date: 2023-11-10 19:21:05
On Fri, 10 Nov 2023 11:18:23 +0000 Dipendra Khadka wrote:
Syzkaller found a null pointer dereference in nsim_bpf
originating from the lack of a null check for state.
This patch fixes the issue by adding a check for state
in two functions nsim_prog_set_loaded() and nsim_setup_prog_hw_checks()
Reported-by: syzbot+44c2416196b7c607f226@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com./bug?extid=44c2416196b7c607f226
Fixes: 31d3ad832948 ("netdevsim: add bpf offload support")
Don't think so. It's probably due to Stan's extensions / reuse of
the offload infra.
Please put more effort into figuring out when and why this started
happening. Describe your findings in the commit message.
Current patch looks too much like a bandaid.
Before you repost read:
https://www.kernel.org/doc/html/next/process/maintainer-netdev.html
--
pw-bot: cr
pv-bot: syz
pv-bot: 24h
From: Stanislav Fomichev <hidden> Date: 2023-11-10 19:23:38
On 11/10, Jakub Kicinski wrote:
On Fri, 10 Nov 2023 11:18:23 +0000 Dipendra Khadka wrote:
quoted
Syzkaller found a null pointer dereference in nsim_bpf
originating from the lack of a null check for state.
This patch fixes the issue by adding a check for state
in two functions nsim_prog_set_loaded() and nsim_setup_prog_hw_checks()
Reported-by: syzbot+44c2416196b7c607f226@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com./bug?extid=44c2416196b7c607f226
Fixes: 31d3ad832948 ("netdevsim: add bpf offload support")
Don't think so. It's probably due to Stan's extensions / reuse of
the offload infra.
Please put more effort into figuring out when and why this started
happening. Describe your findings in the commit message.
Current patch looks too much like a bandaid.
Before you repost read:
https://www.kernel.org/doc/html/next/process/maintainer-netdev.html