Re: [PATCH bpf v2] bpf: Fix NULL pointer dereference in bpf_sock_from_file

"Kumar Kartikeya Dwivedi" <[email protected]>
Newsgroups org.kernel.vger.bpf,org.kernel.vger.netdev
Message-ID <[email protected]>
On Fri Aug 21, 2026 at 7:30 PM CEST, Andrii Nakryiko wrote:
> On Thu, Aug 20, 2026 at 8:25 AM Syeda Mahnur Asif <[email protected]> wrote:
>>
>> bpf_sock_from_file should not dereference a NULL file pointer.
>> KASAN detects a null-ptr-deref when eBPF tracing
>> fentry/fexit programs are attached to points such as
>> __mmap_region and file_map_prot_check kernel functions. This can
>> result in a NULL file pointer flowing from context to the helper.
>>
>> A minimal check before dereferencing can fix this.
>>
>> Fixes: b60da4955f53 ("bpf: Only provide bpf_sock_from_file with CONFIG_NET")
>> Reviewed-by: Emil Tsalapatis <[email protected]>
>> Signed-off-by: Syeda Mahnur Asif <[email protected]>
>> ---
>> v2:
>> - Added Reviewed-by from Emil Tsalapatis
>> - Fixed name in Signed-off-by
>>
>>  net/core/filter.c | 5 ++++-
>>  1 file changed, 4 insertions(+), 1 deletion(-)
>>
>> diff --git a/net/core/filter.c b/net/core/filter.c
>> index 16845987b244..7c3caae4bafc 100644
>> --- a/net/core/filter.c
>> +++ b/net/core/filter.c
>> @@ -12182,7 +12182,10 @@ const struct bpf_func_proto bpf_skc_to_mptcp_sock_proto = {
>>
>>  BPF_CALL_1(bpf_sock_from_file, struct file *, file)
>>  {
>> -       return (unsigned long)sock_from_file(file);
>> +       if (file)
>> +               return (unsigned long)sock_from_file(file);
>
> given this is a legacy ARG_PTR_TO_BTF_ID, it can be not just NULL, but
> also a) small value bogus "pointer" resulting from NULL + offset
> calculation and/or b) just random garbage casted to struct file
> pointer with bpf_core_cast() (maybe this hole we've closed with
> explicitly untrusted, not sure).
>
> Either way, this is not a sufficient fix at least.
>
> But I wonder if the proper fix is actually to mark this (and other
> similar) argument as explicitly requiring trusted PTR_TO_BTF_ID?
>
> Thoughts?
>

+1, should bite the bullet and accelerate deprecation of legacy PTR_TO_BTF_ID.
We can mark specific arguments / fields in structs as trusted where there is a
legitimate use case and the kernel guarantees their lifetime appropriately.

>> +
>> +       return (unsigned long)NULL;
>>  }
>>
>>  BTF_ID_LIST(bpf_sock_from_file_btf_ids)
>> --
>> 2.53.0
>>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.