linux/kernel/bpf
Weiming Shi 6db1ce73e9
bpf: Reject dev-bound-only programs on other devices
__bpf_offload_dev_match() falls back to comparing offdev pointers after an
exact netdev mismatch. Bound-only programs normally have NULL offdevs, so
unrelated netdevs compare equal. A bound-only program on an
offload-registered netdev can instead inherit a real offdev and match a
sibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use
bpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs
specialized for the bound driver on the target driver's xdp_buff. Running a
veth-bound program on tun reads beyond tun's bare stack xdp_buff as a
veth_xdp_buff.

  Oops: general protection fault, probably for non-canonical address
  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
  RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)
  Call Trace:
   ...
   tun_build_skb (drivers/net/tun.c:1739)
   tun_get_user (drivers/net/tun.c:1856)
   tun_chr_write_iter (drivers/net/tun.c:2091)
   vfs_write (fs/read_write.c:595 fs/read_write.c:687)
   ksys_write (fs/read_write.c:739)
   do_syscall_64 (arch/x86/entry/syscall_64.c:84)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
  Kernel panic - not syncing: Fatal exception in interrupt

Restrict non-offloaded programs to exact netdev matches and retain the
shared-offdev fallback only for genuinely offloaded multi-port programs.

Fixes: 2b3486bc2d ("bpf: Introduce device-bound XDP programs")
Reported-by: <co+ac0a8c41de69121d@bugs.sh>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20260917161335.1020405-2-bestswngs@gmail.com/
Link: https://patch.msgid.link/20260920132303.4109240-3-bestswngs@gmail.com
2026-09-23 02:19:02 +00:00
..
preload umd: Remove usermode driver framework 2025-07-26 21:03:04 +02:00
arena.c bpf: Mark existing lock-safe kfuncs with KF_SPINLOCK_SAFE 2026-08-06 10:58:04 +02:00
arraymap.c bpf: Fix percpu map update indexing with sparse CPU IDs 2026-08-21 10:41:27 -07:00
backtrack.c bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks 2026-09-02 11:13:21 -07:00
bloom_filter.c bpf: Harden bloom filter sizing and indexing on 32-bit kernels 2026-08-05 11:45:20 -07:00
bpf_cgrp_storage.c bpf: Remove gfp_flags plumbing from bpf_local_storage_update() 2026-04-10 21:22:32 -07:00
bpf_inode_storage.c bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized 2026-06-30 16:31:56 +02:00
bpf_insn_array.c bpf: Lose const-ness of map in map_check_btf() 2026-02-27 15:39:00 -08:00
bpf_iter.c bpf: Reject non-scalar bpf_loop iteration counts 2026-09-05 20:50:13 -07:00
bpf_local_storage.c bpf: Remove gfp_flags plumbing from bpf_local_storage_update() 2026-04-10 21:22:32 -07:00
bpf_lru_list.c bpf: Fix NMI/tracepoint re-entry deadlock on lru locks 2026-06-07 18:46:13 -07:00
bpf_lru_list.h bpf: Fix NMI/tracepoint re-entry deadlock on lru locks 2026-06-07 18:46:13 -07:00
bpf_lsm_proto.c bpf: annotate file argument as __nullable in bpf_lsm_mmap_file 2025-12-21 10:56:33 -08:00
bpf_lsm.c bpf: Rename ARG_CONST_SIZE{,_OR_ZERO} to ARG_MEM_SIZE{,_OR_ZERO} 2026-08-03 00:29:14 +02:00
bpf_struct_ops.c bpf: Support __arena and __arena__nullable on struct_ops arguments 2026-08-08 03:03:26 -07:00
bpf_task_storage.c bpf: Remove gfp_flags plumbing from bpf_local_storage_update() 2026-04-10 21:22:32 -07:00
btf_iter.c
btf_relocate.c
btf.c bpf: Bound ownership depth through local kptrs and graph roots 2026-09-19 05:26:43 +00:00
cfg.c bpf: don't rewrite bpf_fastcall patterns entered by a jump 2026-09-03 18:55:40 -07:00
cgroup_iter.c bpf: add new BPF_CGROUP_ITER_CHILDREN control option 2026-01-27 09:05:54 -08:00
cgroup.c bpf: Reject negative optlen in cgroup getsockopt hook 2026-08-17 11:33:29 +02:00
check_btf.c bpf: Apply CO-RE relocations before subprogram validation 2026-09-17 18:01:42 -07:00
cnum_defs.h bpf: Export cnum_umin/umax() helpers for netronome driver 2026-04-27 10:09:48 -07:00
cnum.c bpf: representation and basic operations on circular numbers 2026-04-24 18:14:17 -07:00
const_fold.c bpf: Introduce global percpu data 2026-08-13 10:27:40 -07:00
core.c bpf: Make post-verification instruction rewrites killable 2026-09-17 18:01:42 -07:00
cpumap.c bpf: Add missing XDP_ABORTED handling in cpumap 2026-03-03 08:37:21 -08:00
cpumask.c bpf: Require a BPF cpumask for bpf_cpumask_populate() 2026-07-12 01:52:36 +02:00
crypto.c bpf: Check params size before reading reserved fields 2026-09-19 23:25:17 +00:00
devmap.c bpf: Run generic devmap egress prog on private skb 2026-06-12 18:21:01 -07:00
diagnostics.c treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
diagnostics.h bpf: Report Policy helper and kfunc errors 2026-08-15 11:15:17 -07:00
disasm.c bpf: update disasm.c to print BPF_PROBE_ATOMIC as atomics 2026-09-03 18:54:45 -07:00
disasm.h
dispatcher.c bpf: dispatcher: Allocate bpf_dispatcher->rw_image with vzalloc() 2026-07-22 17:26:39 +02:00
dmabuf_iter.c bpf: Fix truncated dmabuf iterator reads 2025-12-09 23:48:34 -08:00
fixups.c bpf: Make post-verification instruction rewrites killable 2026-09-17 18:01:42 -07:00
hashtab.c bpf: Fix u32 overflow issue in map batch operations 2026-09-13 21:58:40 -07:00
helpers.c bpf: Require CAP_PERFMON for kfuncs reading memory 2026-09-10 16:55:47 -07:00
inode.c bpf-next-7.2 2026-06-17 09:18:14 +01:00
Kconfig bpf: Update the bpf_prog_calc_tag to use SHA256 2025-09-18 19:10:20 -07:00
kmem_cache_iter.c
link_iter.c bpf: Clean up individual BTF_ID code 2025-07-16 18:34:42 -07:00
liveness.c treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
local_storage.c bpf: Fix percpu map update indexing with sparse CPU IDs 2026-08-21 10:41:27 -07:00
log.c treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
lpm_trie.c bpf: Allow LPM map access from sleepable BPF programs 2026-06-09 12:42:22 -07:00
Makefile bpf: Add verifier diagnostics report helpers 2026-08-15 11:11:16 -07:00
map_in_map.c bpf: Reject exclusive maps as inner maps in map-in-map 2026-06-01 18:36:40 -07:00
map_in_map.h
map_iter.c bpf: Implement iteration ops for resizable hashtab 2026-06-05 08:00:08 -07:00
memalloc.c bpf: Fix UAF due to concurrent consumption of ttrace lists in alloc_bulk 2026-09-13 19:37:20 -07:00
mmap_unlock_work.h bpf: Fix mmap_lock leak in irq_work path 2026-08-08 10:25:36 +02:00
mprog.c
net_namespace.c bpf: Fix potential UAF in bpf_netns_link_update_prog 2026-07-30 15:28:46 -07:00
offload.c bpf: Reject dev-bound-only programs on other devices 2026-09-23 02:19:02 +00:00
percpu_freelist.c bpf: Fix infinite loop in pcpu_freelist push with one possible CPU 2026-08-20 20:44:16 +02:00
percpu_freelist.h bpf: Fix infinite loop in pcpu_freelist push with one possible CPU 2026-08-20 20:44:16 +02:00
prog_iter.c bpf: Clean up individual BTF_ID code 2025-07-16 18:34:42 -07:00
queue_stack_maps.c bpf: Drop duplicate blank lines in kernel/bpf/ 2026-08-13 10:27:40 -07:00
range_tree.c bpf: arena: Reintroduce memcg accounting 2026-01-02 14:31:59 -08:00
range_tree.h bpf: Introduce range_tree data structure and use it in bpf arena 2024-11-13 13:52:45 -08:00
relo_core.c
reuseport_array.c
ringbuf.c bpf: Fix available-data accounting on 32-bit wrap in overwrite mode 2026-08-14 15:20:37 -07:00
rqspinlock.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.2-rc7 2026-08-07 23:04:17 +02:00
rqspinlock.h rqspinlock: Protect waiters in queue from stalls 2025-03-19 08:03:05 -07:00
stackmap.c bpf: Mark faultable stack helpers as sleepable 2026-09-03 19:22:52 -07:00
states.c bpf: Compare stack frames in regs_exact() 2026-09-19 05:25:14 +00:00
stream.c bpf: Add bpf_stream_print_stack stack dumping kfunc 2026-02-03 10:41:16 -08:00
syscall.c bpf: Skip unsettled links in link iterator 2026-09-17 15:00:17 -07:00
sysfs_btf.c Driver core changes for 6.17-rc1 2025-07-29 12:15:39 -07:00
task_iter.c bpf: Fix mmap_lock leak in irq_work path 2026-08-08 10:25:36 +02:00
tcx.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
tnum.c bpf: Simplify tnum_step() 2026-03-24 08:45:29 -07:00
token.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
trampoline.c bpf: Make bpf_trampoline_multi_detach return void 2026-08-13 02:52:23 +02:00
verifier.c bpf: Prevent variable arena/non-arena register contents 2026-09-22 19:34:04 +00:00