include/linux/bpf.h | 9 ++++----- kernel/bpf/trampoline.c | 16 +++++++++++++--- kernel/trace/bpf_trace.c | 2 +- 3 files changed, 18 insertions(+), 9 deletions(-)
From: Hui Zhu <zhuhui@kylinos.cn> This series fixes a UAF in bpf_trampoline_multi_attach_free() where old_image is freed while ftrace still calls into it, and makes bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa. Patch 1 fixes the UAF. Patch 2 is an independent cleanup that changes the return type to void and drops the WARN_ON_ONCE at the call site. Changelog: v5: According to the comments of bot+bpf-ci, split the single patch into two: the bug fix and the return-type cleanup. v4: According to the comments of bot+bpf-ci, add Fixes: and update comments of bpf_trampoline_multi_attach_free. v3: According to the comments of Jiri Olsa, drop patches 2/3 and the prog-side machinery. keep only the simplified image-side fix in bpf_trampoline_multi_attach_free() and make bpf_trampoline_multi_detach() return void. v2: Folded v1's two detach patches into patch 1. According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on cur_image so it stays alive while ftrace may still call into it. Make bpf_trampoline_multi_detach() return void. Fix the same UAF in standard (non-multi) trampolines. According to the comments of sashiko, Fix the prog UAF in bpf_trampoline_multi_attach() rollback. Leak the trampoline in bpf_trampoline_put() when cur_image is left by a rollback. Hui Zhu (2): bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure bpf: Make bpf_trampoline_multi_detach return void include/linux/bpf.h | 9 ++++----- kernel/bpf/trampoline.c | 16 +++++++++++++--- kernel/trace/bpf_trace.c | 2 +- 3 files changed, 18 insertions(+), 9 deletions(-) -- 2.53.0
On Tue Aug 11, 2026 at 4:46 AM CEST, Hui Zhu wrote: > From: Hui Zhu <zhuhui@kylinos.cn> > > This series fixes a UAF in bpf_trampoline_multi_attach_free() where > old_image is freed while ftrace still calls into it, and makes > bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa. > > Patch 1 fixes the UAF. Patch 2 is an independent cleanup that > changes the return type to void and drops the WARN_ON_ONCE at the > call site. > > Changelog: > v5: > According to the comments of bot+bpf-ci, split the single patch into > two: the bug fix and the return-type cleanup. > v4: > According to the comments of bot+bpf-ci, add Fixes: and update comments > of bpf_trampoline_multi_attach_free. > v3: > According to the comments of Jiri Olsa, drop patches 2/3 and the > prog-side machinery. > keep only the simplified image-side fix in > bpf_trampoline_multi_attach_free() and make > bpf_trampoline_multi_detach() return void. > v2: > Folded v1's two detach patches into patch 1. > According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on > cur_image so it stays alive while ftrace may still call into it. > Make bpf_trampoline_multi_detach() return void. > Fix the same UAF in standard (non-multi) trampolines. > According to the comments of sashiko, Fix the prog UAF in > bpf_trampoline_multi_attach() rollback. > Leak the trampoline in bpf_trampoline_put() when cur_image is left > by a rollback. > Applied, thanks. > Hui Zhu (2): > bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure > bpf: Make bpf_trampoline_multi_detach return void > > include/linux/bpf.h | 9 ++++----- > kernel/bpf/trampoline.c | 16 +++++++++++++--- > kernel/trace/bpf_trace.c | 2 +- > 3 files changed, 18 insertions(+), 9 deletions(-)
On Tue, Aug 11, 2026 at 10:46:18AM +0800, Hui Zhu wrote: > From: Hui Zhu <zhuhui@kylinos.cn> > > This series fixes a UAF in bpf_trampoline_multi_attach_free() where > old_image is freed while ftrace still calls into it, and makes > bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa. > > Patch 1 fixes the UAF. Patch 2 is an independent cleanup that > changes the return type to void and drops the WARN_ON_ONCE at the > call site. > > Changelog: > v5: > According to the comments of bot+bpf-ci, split the single patch into > two: the bug fix and the return-type cleanup. > v4: > According to the comments of bot+bpf-ci, add Fixes: and update comments > of bpf_trampoline_multi_attach_free. > v3: > According to the comments of Jiri Olsa, drop patches 2/3 and the > prog-side machinery. > keep only the simplified image-side fix in > bpf_trampoline_multi_attach_free() and make > bpf_trampoline_multi_detach() return void. > v2: > Folded v1's two detach patches into patch 1. > According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on > cur_image so it stays alive while ftrace may still call into it. > Make bpf_trampoline_multi_detach() return void. > Fix the same UAF in standard (non-multi) trampolines. > According to the comments of sashiko, Fix the prog UAF in > bpf_trampoline_multi_attach() rollback. > Leak the trampoline in bpf_trampoline_put() when cur_image is left > by a rollback. > > Hui Zhu (2): > bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure > bpf: Make bpf_trampoline_multi_detach return void Acked-by: Jiri Olsa <jolsa@kernel.org> thanks, jirka
On 11/8/26 10:46, Hui Zhu wrote: > From: Hui Zhu <zhuhui@kylinos.cn> > > This series fixes a UAF in bpf_trampoline_multi_attach_free() where > old_image is freed while ftrace still calls into it, and makes > bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa. > > Patch 1 fixes the UAF. Patch 2 is an independent cleanup that > changes the return type to void and drops the WARN_ON_ONCE at the > call site. The UAF issue was reported by Sashiko when reviewing "bpf: Add tracing_multi link support for bpf progs" [1]. The fix and the cleanup look good to me. Acked-by: Leon Hwang <leon.hwang@linux.dev> [1] https://sashiko.dev/#/message/20260809153308.5331D1F000E9%40smtp.kernel.org > [...]
© 2016 - 2026 Red Hat, Inc.