Re: [PATCH bpf-next v2 3/6] bpf: Reject a store through a fault prone pointer

Eduard Zingerman <[email protected]>
Newsgroups org.kernel.vger.bpf
Message-ID <[email protected]>
On Fri, 2026-08-14 at 23:52 +0200, Daniel Borkmann wrote:
> check_ptr_to_btf_access() allows the program to store before the default
> BTF access path gets to reject a non read access. ac65c710cc64 ("bpf:
> Reject writes through untrusted BTF pointers") closed that for a
> PTR_UNTRUSTED pointer, but a bare PTR_TO_BTF_ID may fault on a dereference
> just the same and is let through.
> 
> A BPF_LDX gets the BPF_PROBE_MEM rewrite in bpf_convert_ctx_accesses()
> and a bad address is handled, but a BPF_STX does not and cannot, there
> is no probed store to rewrite. The store is emitted as a plain one without
> an exception table entry and a bad address panics the kernel.
> 
> A bpf_qdisc program can reach this, bpf_qdisc_btf_struct_access() permits a
> write to Qdisc::limit and Qdisc::next_sched is a plain struct Qdisc pointer
> which the walk turns into the compat type:
> 
>   struct Qdisc *next = sch->next_sched;
> 
>   next->limit = 1000;
> 
>   BUG: kernel NULL pointer dereference, address: 0000000000000014
>   RIP: 0010:bpf_prog_c6e14e7f32c8e325_bpf_fifo_enqueue+0x3a/0x12b
>   Code: [...] bf e8 03 00 00 <89> 7e 14 41 8b 7f 14 [...]
>   Kernel panic - not syncing: Fatal exception in interrupt
> 
> Fix by widen the check to bpf_may_fault_on_deref() so that it covers both.
> 
> Fixes: 27ae7997a661 ("bpf: Introduce BPF_PROG_TYPE_STRUCT_OPS")
> Signed-off-by: Daniel Borkmann <[email protected]>
> ---
>  v1 -> v2:
>    - new patch
> 
>  kernel/bpf/verifier.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 2e6992569187..6610e2437047 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -5789,7 +5789,7 @@ static int check_ptr_to_btf_access(struct bpf_verifier_env *env,
>  		return -EACCES;
>  	}
>  
> -	if (atype != BPF_READ && (type_flag(reg->type) & PTR_UNTRUSTED)) {
> +	if (atype != BPF_READ && bpf_may_fault_on_deref(reg->type)) {

The change is correct, but it appears that the if condition could be
simplified as just 'atype != BPF_READ'.
The function is named check_ptr_to_btf_access() and it is only called
when reg->type == PTR_TO_BTF_ID.

>  		verbose(env, "only read is supported\n");
>  		return -EACCES;
>  	}
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.