Thread (8 messages) flat view 8 messages, 5 authors, 6d ago

Re: [PATCH net] net/sched: cls_bpf: reject dev-bound programs bound to a different device

From: Paolo Abeni <pabeni@redhat.com>
Date: 2026-08-13 09:06:28
Also in: bpf, stable

On 8/9/26 11:44 AM, Jamal Hadi Salim wrote:
cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
program's bound netdev matches the TC netdev the classifier is being
attached to. This let a program loaded with prog_ifindex for device A be
attached via cls_bpf + skip_sw to device B; deleting device A then
destroyed the program's offload state while it was still attached to
device B, triggering a netdevsim WARN (panic with panic_on_warn=1).

Mirror the XDP attach path (net/core/dev.c) and reject the attach with
-EINVAL when a dev-bound program's bound device does not match the
target device.

Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device")
Reported-by: vega@nebusec.ai
Tested-by: Victor Nogueira <redacted>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
I understand that Jakub prefers going with this patch (with a correct
fixes tag), so waiting for such tag landing here ;)

/P
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help