Thread (3 messages) 3 messages, 3 authors, 17d ago

Re: [PATCH bpf] bpf: Fix out-of-bounds read of rtt_min in sock_ops

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-09-12 18:21:08
Also in: bpf, lkml

Hello:

This patch was applied to bpf/bpf.git (master)
by Alexei Starovoitov [off-list ref]:

On Thu,  3 Sep 2026 18:09:20 +0800 you wrote:
A sockops prog reading skops->rtt_min never checks the sk type: on the
tcp_conn_request() path sock_ops->sk is a request_sock (non-full), and the
ctx rewrite casts it to a tcp_sock (full) and reads rtt_min past the end of
the request_sock, returning dirty adjacent memory.

	SEC("sockops")
	int prog(struct bpf_sock_ops *skops)
	{
		switch (skops->op) {
		case BPF_SOCK_OPS_RWND_INIT:
			leak = skops->rtt_min;   /* reads the request_sock OOB */
		...
		}
	}

[...]
Here is the summary with links:
  - [bpf] bpf: Fix out-of-bounds read of rtt_min in sock_ops
    https://git.kernel.org/bpf/bpf/c/75f8cf22463d

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help