Re: [PATCH bpf v2] bpf: Fix NULL pointer dereference in bpf_sock_from_file

Andrii Nakryiko <[email protected]>
Newsgroups org.kernel.vger.bpf,org.kernel.vger.netdev
Message-ID <CAEf4BzZd7BDdJrNb+N3uktbwMJRHjUFzG1xfzmTDibEmAKX8gA@mail.gmail.com>
On Thu, Aug 20, 2026 at 8:25 AM Syeda Mahnur Asif <[email protected]> wrote:
>
> bpf_sock_from_file should not dereference a NULL file pointer.
> KASAN detects a null-ptr-deref when eBPF tracing
> fentry/fexit programs are attached to points such as
> __mmap_region and file_map_prot_check kernel functions. This can
> result in a NULL file pointer flowing from context to the helper.
>
> A minimal check before dereferencing can fix this.
>
> Fixes: b60da4955f53 ("bpf: Only provide bpf_sock_from_file with CONFIG_NET")
> Reviewed-by: Emil Tsalapatis <[email protected]>
> Signed-off-by: Syeda Mahnur Asif <[email protected]>
> ---
> v2:
> - Added Reviewed-by from Emil Tsalapatis
> - Fixed name in Signed-off-by
>
>  net/core/filter.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/net/core/filter.c b/net/core/filter.c
> index 16845987b244..7c3caae4bafc 100644
> --- a/net/core/filter.c
> +++ b/net/core/filter.c
> @@ -12182,7 +12182,10 @@ const struct bpf_func_proto bpf_skc_to_mptcp_sock_proto = {
>
>  BPF_CALL_1(bpf_sock_from_file, struct file *, file)
>  {
> -       return (unsigned long)sock_from_file(file);
> +       if (file)
> +               return (unsigned long)sock_from_file(file);

given this is a legacy ARG_PTR_TO_BTF_ID, it can be not just NULL, but
also a) small value bogus "pointer" resulting from NULL + offset
calculation and/or b) just random garbage casted to struct file
pointer with bpf_core_cast() (maybe this hole we've closed with
explicitly untrusted, not sure).

Either way, this is not a sufficient fix at least.

But I wonder if the proper fix is actually to mark this (and other
similar) argument as explicitly requiring trusted PTR_TO_BTF_ID?

Thoughts?

> +
> +       return (unsigned long)NULL;
>  }
>
>  BTF_ID_LIST(bpf_sock_from_file_btf_ids)
> --
> 2.53.0
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.