Re: [PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure

"Kumar Kartikeya Dwivedi" <[email protected]>
Newsgroups org.kernel.vger.linux-trace-kernel,org.kernel.vger.bpf,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Tue Aug 11, 2026 at 4:46 AM CEST, Hui Zhu wrote:
> From: Hui Zhu <[email protected]>
>
> This series fixes a UAF in bpf_trampoline_multi_attach_free() where
> old_image is freed while ftrace still calls into it, and makes
> bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa.
>
> Patch 1 fixes the UAF.  Patch 2 is an independent cleanup that
> changes the return type to void and drops the WARN_ON_ONCE at the
> call site.
>
> Changelog:
> v5:
> According to the comments of bot+bpf-ci, split the single patch into
> two: the bug fix and the return-type cleanup.
> v4:
> According to the comments of bot+bpf-ci, add Fixes: and update comments
> of bpf_trampoline_multi_attach_free.
> v3:
> According to the comments of Jiri Olsa, drop patches 2/3 and the
> prog-side machinery.
> keep only the simplified image-side fix in
> bpf_trampoline_multi_attach_free() and make
> bpf_trampoline_multi_detach() return void.
> v2:
> Folded v1's two detach patches into patch 1.
> According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on
> cur_image so it stays alive while ftrace may still call into it.
> Make bpf_trampoline_multi_detach() return void.
> Fix the same UAF in standard (non-multi) trampolines.
> According to the comments of sashiko, Fix the prog UAF in
> bpf_trampoline_multi_attach() rollback.
> Leak the trampoline in bpf_trampoline_put() when cur_image is left
> by a rollback.
>

Applied, thanks.

> Hui Zhu (2):
>   bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure
>   bpf: Make bpf_trampoline_multi_detach return void
>
>  include/linux/bpf.h      |  9 ++++-----
>  kernel/bpf/trampoline.c  | 16 +++++++++++++---
>  kernel/trace/bpf_trace.c |  2 +-
>  3 files changed, 18 insertions(+), 9 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.