Re: [PATCH bpf-next v3] bpf: Fix stack out-of-bounds write in cgroup link update

Leon Hwang <[email protected]>
Newsgroups org.kernel.vger.bpf,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 22/8/26 03:35, Andrii Nakryiko wrote:
> On Fri, Aug 21, 2026 at 3:26 AM Leon Hwang <[email protected]> wrote:
[...]
>>
>> Any issue of checking CAP_NET_ADMIN for BPF_LINK_UPDATE?
>>
>> If no, checking CAP_NET_ADMIN for BPF_LINK_UPDATE looks okay.
>>
> 
> Why do we need extra capability checks during LINK_UPDATE if we
> already performed the check during LINK_CREATE? If you pass link fd to
> some process that doesn't have CAP_NET_ADMIN, but has link fd and
> another validated prog fd, they should be able to update the
> underlying program without extra checks, IMO.
> 
What if a pinned link is updated by non-CAP_NET_ADMIN users? I (LLM)
verified the case by the selftest [1]. Is this case allowed intentionally?

[1] https://github.com/Asphaltt/bpf/commits/bpf/link-update-issue/v1/

Thanks,
Leon
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.