[PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure

Hui Zhu posted 2 patches 1 month, 2 weeks ago
include/linux/bpf.h      |  9 ++++-----
kernel/bpf/trampoline.c  | 16 +++++++++++++---
kernel/trace/bpf_trace.c |  2 +-
3 files changed, 18 insertions(+), 9 deletions(-)
[PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure
Posted by Hui Zhu 1 month, 2 weeks ago
From: Hui Zhu <zhuhui@kylinos.cn>

This series fixes a UAF in bpf_trampoline_multi_attach_free() where
old_image is freed while ftrace still calls into it, and makes
bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa.

Patch 1 fixes the UAF.  Patch 2 is an independent cleanup that
changes the return type to void and drops the WARN_ON_ONCE at the
call site.

Changelog:
v5:
According to the comments of bot+bpf-ci, split the single patch into
two: the bug fix and the return-type cleanup.
v4:
According to the comments of bot+bpf-ci, add Fixes: and update comments
of bpf_trampoline_multi_attach_free.
v3:
According to the comments of Jiri Olsa, drop patches 2/3 and the
prog-side machinery.
keep only the simplified image-side fix in
bpf_trampoline_multi_attach_free() and make
bpf_trampoline_multi_detach() return void.
v2:
Folded v1's two detach patches into patch 1.
According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on
cur_image so it stays alive while ftrace may still call into it.
Make bpf_trampoline_multi_detach() return void.
Fix the same UAF in standard (non-multi) trampolines.
According to the comments of sashiko, Fix the prog UAF in
bpf_trampoline_multi_attach() rollback.
Leak the trampoline in bpf_trampoline_put() when cur_image is left
by a rollback.

Hui Zhu (2):
  bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure
  bpf: Make bpf_trampoline_multi_detach return void

 include/linux/bpf.h      |  9 ++++-----
 kernel/bpf/trampoline.c  | 16 +++++++++++++---
 kernel/trace/bpf_trace.c |  2 +-
 3 files changed, 18 insertions(+), 9 deletions(-)

-- 
2.53.0
Re: [PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure
Posted by Kumar Kartikeya Dwivedi 1 month, 2 weeks ago
On Tue Aug 11, 2026 at 4:46 AM CEST, Hui Zhu wrote:
> From: Hui Zhu <zhuhui@kylinos.cn>
>
> This series fixes a UAF in bpf_trampoline_multi_attach_free() where
> old_image is freed while ftrace still calls into it, and makes
> bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa.
>
> Patch 1 fixes the UAF.  Patch 2 is an independent cleanup that
> changes the return type to void and drops the WARN_ON_ONCE at the
> call site.
>
> Changelog:
> v5:
> According to the comments of bot+bpf-ci, split the single patch into
> two: the bug fix and the return-type cleanup.
> v4:
> According to the comments of bot+bpf-ci, add Fixes: and update comments
> of bpf_trampoline_multi_attach_free.
> v3:
> According to the comments of Jiri Olsa, drop patches 2/3 and the
> prog-side machinery.
> keep only the simplified image-side fix in
> bpf_trampoline_multi_attach_free() and make
> bpf_trampoline_multi_detach() return void.
> v2:
> Folded v1's two detach patches into patch 1.
> According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on
> cur_image so it stays alive while ftrace may still call into it.
> Make bpf_trampoline_multi_detach() return void.
> Fix the same UAF in standard (non-multi) trampolines.
> According to the comments of sashiko, Fix the prog UAF in
> bpf_trampoline_multi_attach() rollback.
> Leak the trampoline in bpf_trampoline_put() when cur_image is left
> by a rollback.
>

Applied, thanks.

> Hui Zhu (2):
>   bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure
>   bpf: Make bpf_trampoline_multi_detach return void
>
>  include/linux/bpf.h      |  9 ++++-----
>  kernel/bpf/trampoline.c  | 16 +++++++++++++---
>  kernel/trace/bpf_trace.c |  2 +-
>  3 files changed, 18 insertions(+), 9 deletions(-)
Re: [PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure
Posted by Jiri Olsa 1 month, 2 weeks ago
On Tue, Aug 11, 2026 at 10:46:18AM +0800, Hui Zhu wrote:
> From: Hui Zhu <zhuhui@kylinos.cn>
> 
> This series fixes a UAF in bpf_trampoline_multi_attach_free() where
> old_image is freed while ftrace still calls into it, and makes
> bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa.
> 
> Patch 1 fixes the UAF.  Patch 2 is an independent cleanup that
> changes the return type to void and drops the WARN_ON_ONCE at the
> call site.
> 
> Changelog:
> v5:
> According to the comments of bot+bpf-ci, split the single patch into
> two: the bug fix and the return-type cleanup.
> v4:
> According to the comments of bot+bpf-ci, add Fixes: and update comments
> of bpf_trampoline_multi_attach_free.
> v3:
> According to the comments of Jiri Olsa, drop patches 2/3 and the
> prog-side machinery.
> keep only the simplified image-side fix in
> bpf_trampoline_multi_attach_free() and make
> bpf_trampoline_multi_detach() return void.
> v2:
> Folded v1's two detach patches into patch 1.
> According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on
> cur_image so it stays alive while ftrace may still call into it.
> Make bpf_trampoline_multi_detach() return void.
> Fix the same UAF in standard (non-multi) trampolines.
> According to the comments of sashiko, Fix the prog UAF in
> bpf_trampoline_multi_attach() rollback.
> Leak the trampoline in bpf_trampoline_put() when cur_image is left
> by a rollback.
> 
> Hui Zhu (2):
>   bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure
>   bpf: Make bpf_trampoline_multi_detach return void

Acked-by: Jiri Olsa <jolsa@kernel.org>

thanks,
jirka
Re: [PATCH bpf-next v5 0/2] bpf: Fix trampoline image UAF on multi detach failure
Posted by Leon Hwang 1 month, 2 weeks ago
On 11/8/26 10:46, Hui Zhu wrote:
> From: Hui Zhu <zhuhui@kylinos.cn>
> 
> This series fixes a UAF in bpf_trampoline_multi_attach_free() where
> old_image is freed while ftrace still calls into it, and makes
> bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa.
> 
> Patch 1 fixes the UAF.  Patch 2 is an independent cleanup that
> changes the return type to void and drops the WARN_ON_ONCE at the
> call site.


The UAF issue was reported by Sashiko when reviewing "bpf: Add
tracing_multi link support for bpf progs" [1].

The fix and the cleanup look good to me.

Acked-by: Leon Hwang <leon.hwang@linux.dev>

[1]
https://sashiko.dev/#/message/20260809153308.5331D1F000E9%40smtp.kernel.org

> [...]