mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
bpf: Reject passing scalar NULL to nonnull arg of a global subprog
A global subprogram argument tagged __arg_nonnull is set up as a
non-nullable PTR_TO_MEM. However the verifier does not check against a
scalar NULL, leading to real NULL pointer dereference. Reject it as
well.
Fixes: 94e1c70a34 ("bpf: support 'arg:xxx' btf_decl_tag-based hints for global subprog args")
Signed-off-by: Amery Hung <ameryhung@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://patch.msgid.link/20260723221815.367797-1-ameryhung@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
This commit is contained in:
parent
94515f3a7d
commit
289e680c89
|
|
@ -9189,7 +9189,8 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
|
|||
return ret;
|
||||
if (check_mem_reg(env, reg, argno, arg->mem_size))
|
||||
return -EINVAL;
|
||||
if (!(arg->arg_type & PTR_MAYBE_NULL) && (reg->type & PTR_MAYBE_NULL)) {
|
||||
if (!(arg->arg_type & PTR_MAYBE_NULL) &&
|
||||
(type_may_be_null(reg->type) || bpf_register_is_null(reg))) {
|
||||
bpf_log(log, "%s is expected to be non-NULL\n",
|
||||
reg_arg_name(env, argno));
|
||||
return -EINVAL;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user