From: Pu Lehui <pulehui@huawei.com>
This patch series addresses a few concurrency UAF issues within bpf link update.
v6:
- BPF_F_LINK flag set means the relative id_or_fd is a link, not the object being
attached. We can not get the link while attach a bare prog with relative link.
So passing expected link type from callers of bpf_mprog_attach/detach. (Sashiko)
- Add comment to explain that why ptype == UNSPEC in bpf_mprog_detach. (Emil)
v5: https://lore.kernel.org/bpf/20260721041048.1394085-1-pulehui@huaweicloud.com
- Remove rcu_read_lock_trace as rcu_read_unlock is sufficient. (Mykyta)
- Improve commit msg for patch 2. (Amery)
- Add Reviewed-by tag by Amery.
v4: https://lore.kernel.org/bpf/20260720134547.1289964-1-pulehui@huaweicloud.com
- Add new fix for UAF due to missing link type check in mprog. (Sashiko)
- Add new fix for UAF in bpf_netns_link_update_prog. (Sashiko)
- Include the storage and flags rollbacks to patch4 for sake of code rigor,
as it's hard to make update_effective_progs fail in __cgroup_bpf_attach.
v3: https://lore.kernel.org/bpf/20260720033055.1215477-1-pulehui@huaweicloud.com
- Add new fix for UAF issue when reading bpf link info. (Sashiko)
- Add new fix for storage not restored when update_effective_progs
failed. (Sashiko)
v2: https://lore.kernel.org/bpf/20260717073343.958862-1-pulehui@huaweicloud.com
- Fix invalid access for in-place update when storage changed. (Sashiko)
v1: https://lore.kernel.org/bpf/20260714014659.401063-1-pulehui@huaweicloud.com
Pu Lehui (4):
bpf: Fix potential UAF in bpf_netns_link_update_prog
bpf: Fix UAF due to missing link type check in mprog
bpf: Fix potential UAF when reading bpf link info
bpf, cgroup: Fix storage null-ptr-deref after replacing prog
drivers/net/netkit.c | 13 ++++++-----
include/linux/bpf_mprog.h | 6 ++++--
kernel/bpf/cgroup.c | 44 +++++++++++++++++++++++++++++++++++++-
kernel/bpf/mprog.c | 23 ++++++++++++--------
kernel/bpf/net_namespace.c | 14 +++++++-----
kernel/bpf/syscall.c | 21 ++++++++++++++----
kernel/bpf/tcx.c | 13 ++++++-----
7 files changed, 99 insertions(+), 35 deletions(-)
--
2.34.1