Re: [PATCH bpf v2] bpf: Fix NULL pointer dereference in bpf_sock_from_file
"Kumar Kartikeya Dwivedi" <[email protected]>
| Newsgroups | org.kernel.vger.bpf,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On Fri Aug 21, 2026 at 7:30 PM CEST, Andrii Nakryiko wrote: > On Thu, Aug 20, 2026 at 8:25 AM Syeda Mahnur Asif <[email protected]> wrote: >> >> bpf_sock_from_file should not dereference a NULL file pointer. >> KASAN detects a null-ptr-deref when eBPF tracing >> fentry/fexit programs are attached to points such as >> __mmap_region and file_map_prot_check kernel functions. This can >> result in a NULL file pointer flowing from context to the helper. >> >> A minimal check before dereferencing can fix this. >> >> Fixes: b60da4955f53 ("bpf: Only provide bpf_sock_from_file with CONFIG_NET") >> Reviewed-by: Emil Tsalapatis <[email protected]> >> Signed-off-by: Syeda Mahnur Asif <[email protected]> >> --- >> v2: >> - Added Reviewed-by from Emil Tsalapatis >> - Fixed name in Signed-off-by >> >> net/core/filter.c | 5 ++++- >> 1 file changed, 4 insertions(+), 1 deletion(-) >> >> diff --git a/net/core/filter.c b/net/core/filter.c >> index 16845987b244..7c3caae4bafc 100644 >> --- a/net/core/filter.c >> +++ b/net/core/filter.c >> @@ -12182,7 +12182,10 @@ const struct bpf_func_proto bpf_skc_to_mptcp_sock_proto = { >> >> BPF_CALL_1(bpf_sock_from_file, struct file *, file) >> { >> - return (unsigned long)sock_from_file(file); >> + if (file) >> + return (unsigned long)sock_from_file(file); > > given this is a legacy ARG_PTR_TO_BTF_ID, it can be not just NULL, but > also a) small value bogus "pointer" resulting from NULL + offset > calculation and/or b) just random garbage casted to struct file > pointer with bpf_core_cast() (maybe this hole we've closed with > explicitly untrusted, not sure). > > Either way, this is not a sufficient fix at least. > > But I wonder if the proper fix is actually to mark this (and other > similar) argument as explicitly requiring trusted PTR_TO_BTF_ID? > > Thoughts? > +1, should bite the bullet and accelerate deprecation of legacy PTR_TO_BTF_ID. We can mark specific arguments / fields in structs as trusted where there is a legitimate use case and the kernel guarantees their lifetime appropriately. >> + >> + return (unsigned long)NULL; >> } >> >> BTF_ID_LIST(bpf_sock_from_file_btf_ids) >> -- >> 2.53.0 >>