| From: |
| Sechang Lim <rhkrqnwk98-AT-gmail.com> |
| To: |
| John Fastabend <john.fastabend-AT-gmail.com>, Jakub Sitnicki <jakub-AT-cloudflare.com>, Eric Dumazet <edumazet-AT-google.com>, Kuniyuki Iwashima <kuniyu-AT-google.com>, Paolo Abeni <pabeni-AT-redhat.com>, Willem de Bruijn <willemb-AT-google.com>, "David S . Miller" <davem-AT-davemloft.net>, Jakub Kicinski <kuba-AT-kernel.org> |
| Subject: |
| [PATCH bpf v3 0/2] bpf, sockmap: reject a packet-modifying SK_SKB stream parser |
| Date: |
| Thu, 18 Jun 2026 10:27:06 +0000 |
| Message-ID: |
| <20260618102718.2331468-1-rhkrqnwk98@gmail.com> |
| Cc: |
| Simon Horman <horms-AT-kernel.org>, Bobby Eshleman <bobbyeshleman-AT-gmail.com>, Jiayuan Chen <jiayuan.chen-AT-linux.dev>, netdev-AT-vger.kernel.org, bpf-AT-vger.kernel.org, linux-kernel-AT-vger.kernel.org |
| Archive-link: |
| Article |
A BPF_PROG_TYPE_SK_SKB stream parser runs on strparser's message head,
which can chain skbs through frag_list. A parser that resizes the skb
frees the frag_list segments that strparser still tracks through
skb_nextp, leading to a use-after-free.
A stream parser is only meant to measure the next message, not to modify
the packet, so reject a packet-modifying parser at attach time rather
than working around the resize at runtime.
v3:
- reject the parser at attach time instead of cloning the skb at
runtime (Kuniyuki Iwashima, Jiayuan Chen)
- add a selftest (Bobby Eshleman)
v2:
- https://lore.kernel.org/all/20260612123553.2724240-1-rhkr...
v1:
- https://lore.kernel.org/all/20260609112316.3685738-1-rhkr...
Sechang Lim (2):
bpf, sockmap: fix use-after-free when the stream parser resizes the
skb
selftests/bpf: test rejection of a packet-modifying SK_SKB stream
parser
net/core/sock_map.c | 20 ++++++++++++
.../selftests/bpf/prog_tests/sockmap_strp.c | 31 +++++++++++++++++++
.../selftests/bpf/progs/test_sockmap_strp.c | 7 +++++
3 files changed, 58 insertions(+)
--
2.43.0