From nobody Sat Jul 25 20:47:02 2026 Received: from dggsgout12.his.huawei.com (dggsgout12.his.huawei.com [45.249.212.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 159E6360EE8; Tue, 14 Jul 2026 01:42:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=45.249.212.56 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783993362; cv=none; b=gBP7/Zaswtbp9rnTq6CX3Q7D8JW4HqoZb6pwQEyRglai5AJPevX8HwOnJ1DADjns5+xYLs/rFXx81Zld8p9sYAEuFMSO1DqU/5bE8u813GTTXqEnvPoifTitZNBvWVz2R7uUnJ4DYNL/hed2FS3LRHkWQGEfNtrnoqgaB062nGo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783993362; c=relaxed/simple; bh=TxyDTbPp2PXipIXcyClqbS3UeeIpc8msDZDYyfyZPm4=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=VdEOmb7qCd1bFAI9oP0XVve1/QWb+lAJZOKae7BDuexRz6IfbAsBBGu6NonzbVZG8uqLAzh81ASM7VUYpEDYc8bKd529jEWDHI6VCqGz/u2fQx8dW4zqu5ZKp1lOcY7Afa5aXZCY5vePC+FRqO/45T8HYexjz0nrNdDOViyIWOw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com; spf=none smtp.mailfrom=huaweicloud.com; arc=none smtp.client-ip=45.249.212.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=huaweicloud.com Received: from mail.maildlp.com (unknown [172.19.163.177]) by dggsgout12.his.huawei.com (SkyGuard) with ESMTPS id 4gzhqy39crzKHMLR; Tue, 14 Jul 2026 09:42:06 +0800 (CST) Received: from mail02.huawei.com (unknown [10.116.40.112]) by mail.maildlp.com (Postfix) with ESMTP id 5849B40593; Tue, 14 Jul 2026 09:42:36 +0800 (CST) Received: from ultra.huawei.com (unknown [10.90.53.71]) by APP1 (Coremail) with UTF8SMTPA id cCh0CgAHGHQLlFVqtl2ZBA--.34178S2; Tue, 14 Jul 2026 09:42:36 +0800 (CST) From: Pu Lehui To: bpf@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Eduard Zingerman , Kumar Kartikeya Dwivedi , Yonghong Song , Martin KaFai Lau , Song Liu , Jiri Olsa , Emil Tsalapatis , Pu Lehui , Pu Lehui Subject: [PATCH bpf] bpf, cgroup: Fix storage null-ptr-deref after replacing prog Date: Tue, 14 Jul 2026 01:46:59 +0000 Message-Id: <20260714014659.401063-1-pulehui@huaweicloud.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: cCh0CgAHGHQLlFVqtl2ZBA--.34178S2 X-Coremail-Antispam: 1UD129KBjvJXoW7Zr1fZw1kKr43KrWrAw4Dtwb_yoW8KF1xpF 1DXwnxtw15GwsYvF1kta9FvryfZa10qr15KrZ8Xw1Fka1aqrZYgryxuryqvF9xZFyDur1S vw1Yqr4jkw12vF7anT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUU9F14x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26r1j6r1xM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26r4j 6F4UM28EF7xvwVC2z280aVAFwI0_Gr1j6F4UJwA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_Cr 1j6rxdM2AIxVAIcxkEcVAq07x20xvEncxIr21l5I8CrVACY4xI64kE6c02F40Ex7xfMcIj 6xIIjxv20xvE14v26r1j6r18McIj6I8E87Iv67AKxVWUJVW8JwAm72CE4IkC6x0Yz7v_Jr 0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0EjII2zVCS5cI20VAGYxC7M4IIrI8v6xkF7I0E 8cxan2IY04v7MxkF7I0En4kS14v26r1q6r43MxAIw28IcxkI7VAKI48JMxC20s026xCaFV Cjc4AY6r1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWl x4CE17CEb7AF67AKxVWUtVW8ZwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1j6r 1xMIIF0xvE2Ix0cI8IcVCY1x0267AKxVW8JVWxJwCI42IY6xAIw20EY4v20xvaj40_Jr0_ JF4lIxAIcVC2z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVW8JVW8JrUvcS sGvfC2KfnxnUUI43ZEXa7VUbGQ6JUUUUU== X-CM-SenderInfo: psxovxtxl6x35dzhxuhorxvhhfrp/ Content-Type: text/plain; charset="utf-8" From: Pu Lehui Syzkaller reported a storage null-ptr-deref issue after replacing prog. This occurs in the following scenario: 1. prog A, an empty prog, is attached to a cgrp. 2. prog B uses BPF_MAP_TYPE_PERCPU_CGROUP_STORAGE and calls the bpf_get_local_storage helper. 3. link_update is called to replace prog A with prog B. The reason is that __cgroup_bpf_replace fails to alloc and assign the required cgrp storage for the incoming replacement prog. Consequently, the new prog inherits an uninit storage, leading to null-ptr-deref panic when kick the new prog. Fix this by properly alloc, assign and link the storage for the new prog during link_update. Fixes: 0c991ebc8c69 ("bpf: Implement bpf_prog replacement for an active bpf= _cgroup_link") Signed-off-by: Pu Lehui --- kernel/bpf/cgroup.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/kernel/bpf/cgroup.c b/kernel/bpf/cgroup.c index 4355ccb78a9c..52b5b685a93c 100644 --- a/kernel/bpf/cgroup.c +++ b/kernel/bpf/cgroup.c @@ -1014,6 +1014,7 @@ static void replace_effective_prog(struct cgroup *cgr= p, desc->bpf.effective[atype], lockdep_is_held(&cgroup_mutex)); item =3D &progs->items[pos]; + bpf_cgroup_storages_assign(item->cgroup_storage, pl->storage); WRITE_ONCE(item->prog, pl->link->link.prog); } } @@ -1032,6 +1033,8 @@ static int __cgroup_bpf_replace(struct cgroup *cgrp, struct bpf_cgroup_link *link, struct bpf_prog *new_prog) { + struct bpf_cgroup_storage *new_storage[MAX_BPF_CGROUP_STORAGE_TYPE] =3D {= }; + struct bpf_cgroup_storage *storage[MAX_BPF_CGROUP_STORAGE_TYPE] =3D {}; enum cgroup_bpf_attach_type atype; struct bpf_prog *old_prog; struct bpf_prog_list *pl; @@ -1056,10 +1059,16 @@ static int __cgroup_bpf_replace(struct cgroup *cgrp, if (!found) return -ENOENT; =20 + if (bpf_cgroup_storages_alloc(storage, new_storage, link->link.attach_typ= e, + new_prog, cgrp)) + return -ENOMEM; + cgrp->bpf.revisions[atype] +=3D 1; old_prog =3D xchg(&link->link.prog, new_prog); + bpf_cgroup_storages_assign(pl->storage, storage); replace_effective_prog(cgrp, atype, pl); bpf_prog_put(old_prog); + bpf_cgroup_storages_link(new_storage, cgrp, link->link.attach_type); return 0; } =20 --=20 2.34.1