[PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure

"Hui Zhu" <[email protected]>
Newsgroups gmane.linux.kernel.bpf,gmane.linux.kernel
Message-ID <[email protected]>
From: Hui Zhu <[email protected]>

This series fixes a UAF in bpf_trampoline_multi_attach_free() where
old_image is freed while ftrace still calls into it, and makes
bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa.

Patch 1 fixes the UAF.  Patch 2 is an independent cleanup that
changes the return type to void and drops the WARN_ON_ONCE at the
call site.

Changelog:
v5:
According to the comments of bot+bpf-ci, split the single patch into
two: the bug fix and the return-type cleanup.
v4:
According to the comments of bot+bpf-ci, add Fixes: and update comments
of bpf_trampoline_multi_attach_free.
v3:
According to the comments of Jiri Olsa, drop patches 2/3 and the
prog-side machinery.
keep only the simplified image-side fix in
bpf_trampoline_multi_attach_free() and make
bpf_trampoline_multi_detach() return void.
v2:
Folded v1's two detach patches into patch 1.
According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on
cur_image so it stays alive while ftrace may still call into it.
Make bpf_trampoline_multi_detach() return void.
Fix the same UAF in standard (non-multi) trampolines.
According to the comments of sashiko, Fix the prog UAF in
bpf_trampoline_multi_attach() rollback.
Leak the trampoline in bpf_trampoline_put() when cur_image is left
by a rollback.

Hui Zhu (2):
  bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure
  bpf: Make bpf_trampoline_multi_detach return void

 include/linux/bpf.h      |  9 ++++-----
 kernel/bpf/trampoline.c  | 16 +++++++++++++---
 kernel/trace/bpf_trace.c |  2 +-
 3 files changed, 18 insertions(+), 9 deletions(-)

-- 
2.53.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.