Thread (19 messages) 19 messages, 4 authors, 11d ago

Re: [PATCH bpf 01/11] bpf: Fix bounds check for skb-backed dynptrs

From: Jiayuan Chen <jiayuan.chen@linux.dev>
Date: 2026-09-16 11:52:42
Also in: bpf

On 9/16/26 1:08 PM, Emil Tsalapatis wrote:
The skb_pointer_if_linear() function checks whether a
memory region of length len starting at offset off into
the skb is in the linear area, and returns a pointer to
the region if so. The check currently subtracts between
skb_headlen and offset of the check, and since skb_headlen
is unsigned the subtraction can underflow. This causes the
bounds check to spuriously pass and generate an arbitrary
pointer of the form *(skb->data + off).

The only user of this helper is currently skb-backed BPF
dynptr code. Returning the wrong pointer leads to the
dynptr erroneously being backed with invalid memory.

Ensure the subtraction cannot underflow, and fail the check if
it would. Use u64 arithmetic to also prevent overflow when
calculating (skb_headlen(skb) - off) since off is unsigned.

Fixes: 6f5a630d7c57 ("bpf, net: Introduce skb_pointer_if_linear().")
Reported-by: Nicholas Carlini <redacted>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>

Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev>

quoted hunk ↗ jump to hunk
---

While the code for this is in skbuff.h, the only consumer is
BPF-related, as is the selftest that validates it in the next
patch. So I think it makes sense to route through BPF. If there
are any objections I will split the patch off and resend to net.

  include/linux/skbuff.h | 3 ++-
  1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/include/linux/skbuff.h b/include/linux/skbuff.h
index 421f6fc45..d0c1463db 100644
--- a/include/linux/skbuff.h
+++ b/include/linux/skbuff.h
@@ -4372,7 +4372,8 @@ skb_header_pointer_careful(const struct sk_buff *skb, int offset,
  static inline void * __must_check
  skb_pointer_if_linear(const struct sk_buff *skb, int offset, int len)
  {
-	if (likely(skb_headlen(skb) - offset >= len))
+	if (likely((u64)offset <= skb_headlen(skb) &&
trailing whitespace after "&&"
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help