[PATCH bpf 0/2] bpf: Fix queue/stack map u32 index overflow

[email protected]
Newsgroups org.kernel.vger.bpf,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
From: Yuan Chen <[email protected]>

queue/stack maps address their element storage with a u32 head/tail
index multiplied by value_size. The storage itself is allocated using
64-bit arithmetic, so a map with max_entries * value_size exceeding
U32_MAX can be created, and the u32 multiplication then wraps, making
push/peek/pop operate on the wrong element: map data gets corrupted and
stale values can leak to user space through peek.

The bound check that used to prevent this was removed by c85d69135a91
("bpf: move memory size checks to bpf_map_charge_init()"), which
migrated only the bytes-to-pages conversion and dropped the overflow
guard, so oversized queue/stack maps can be created again.

Patch 1 restores the bound at map creation time: a map whose element
storage would exceed U32_MAX bytes is rejected with -E2BIG, keeping the
u32 index multiplication overflow-free.
Patch 2 adds a regression test covering both map types and a
normal-sized control case.

Verification: built and run in QEMU - oversized queue/stack maps are
rejected with -E2BIG, normal-sized maps still work, and the
queue_stack_map selftest passes.

Yuan Chen (2):
  bpf: Fix queue/stack map u32 index overflow
  selftests/bpf: Add regression test for queue/stack map size limit

 kernel/bpf/queue_stack_maps.c                 |  7 ++++
 .../bpf/prog_tests/queue_stack_map.c          | 34 +++++++++++++++++++
 2 files changed, 41 insertions(+)

-- 
2.54.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.