Unverified Commit 0f78b7af authored by openeuler-ci-bot's avatar openeuler-ci-bot Committed by Gitee
Browse files

!13064 CVE-2024-47702

Merge Pull Request from: @ci-robot 
 
PR sync from: Chen Zhongjin <chenzhongjin@huawei.com>
https://mailweb.openeuler.org/hyperkitty/list/kernel@openeuler.org/message/B4BIMLV53E2LIES6PTLJE5YZ4Y7JI4ZJ/ 
CVE-2024-47702

Chen Zhongjin (1):
  bpf: Fix kabi breakage in struct bpf_insn_access_aux

Yonghong Song (1):
  bpf: Fail verification for sign-extension of packet
    data/data_end/data_meta


-- 
2.25.1
 
https://gitee.com/src-openeuler/kernel/issues/IAYPJQ 
 
Link:https://gitee.com/openeuler/kernel/pulls/13064

 

Reviewed-by: default avatarXu Kuohai <xukuohai@huawei.com>
Reviewed-by: default avatarYe Weihua <yeweihua4@huawei.com>
Signed-off-by: default avatarZhang Peng <zhangpeng362@huawei.com>
parents 2e089ebd 403de23f
Loading
Loading
Loading
Loading
+1 −0
Original line number Diff line number Diff line
@@ -914,6 +914,7 @@ static_assert(__BPF_REG_TYPE_MAX <= BPF_BASE_TYPE_LIMIT);
struct bpf_insn_access_aux {
	enum bpf_reg_type reg_type;
	KABI_FILL_HOLE(bool is_retval) /* is accessing function return value ? */
	KABI_FILL_HOLE(bool is_ldsx)
	union {
		int ctx_field_size;
		struct {
+3 −2
Original line number Diff line number Diff line
@@ -5576,12 +5576,13 @@ static int check_packet_access(struct bpf_verifier_env *env, u32 regno, int off,
/* check access to 'struct bpf_context' fields.  Supports fixed offsets only */
static int check_ctx_access(struct bpf_verifier_env *env, int insn_idx, int off, int size,
			    enum bpf_access_type t, enum bpf_reg_type *reg_type,
			    struct btf **btf, u32 *btf_id, bool *is_retval)
			    struct btf **btf, u32 *btf_id, bool *is_retval, bool is_ldsx)
{
	struct bpf_insn_access_aux info = {
		.reg_type = *reg_type,
		.log = &env->log,
		.is_retval = false,
		.is_ldsx = is_ldsx,
	};
	if (env->ops->is_valid_access &&
@@ -6844,7 +6845,7 @@ static int check_mem_access(struct bpf_verifier_env *env, int insn_idx, u32 regn
			return err;
		err = check_ctx_access(env, insn_idx, off, size, t, &reg_type, &btf,
				       &btf_id, &is_retval);
				       &btf_id, &is_retval, is_ldsx);
		if (err)
			verbose_linfo(env, insn_idx, "; ");
		if (!err && t == BPF_READ && value_regno >= 0) {
+16 −5
Original line number Diff line number Diff line
@@ -8601,13 +8601,16 @@ static bool bpf_skb_is_valid_access(int off, int size, enum bpf_access_type type
		if (off + size > offsetofend(struct __sk_buff, cb[4]))
			return false;
		break;
	case bpf_ctx_range(struct __sk_buff, data):
	case bpf_ctx_range(struct __sk_buff, data_meta):
	case bpf_ctx_range(struct __sk_buff, data_end):
		if (info->is_ldsx || size != size_default)
			return false;
		break;
	case bpf_ctx_range_till(struct __sk_buff, remote_ip6[0], remote_ip6[3]):
	case bpf_ctx_range_till(struct __sk_buff, local_ip6[0], local_ip6[3]):
	case bpf_ctx_range_till(struct __sk_buff, remote_ip4, remote_ip4):
	case bpf_ctx_range_till(struct __sk_buff, local_ip4, local_ip4):
	case bpf_ctx_range(struct __sk_buff, data):
	case bpf_ctx_range(struct __sk_buff, data_meta):
	case bpf_ctx_range(struct __sk_buff, data_end):
		if (size != size_default)
			return false;
		break;
@@ -9051,6 +9054,14 @@ static bool xdp_is_valid_access(int off, int size,
			}
		}
		return false;
	} else {
		switch (off) {
		case offsetof(struct xdp_md, data_meta):
		case offsetof(struct xdp_md, data):
		case offsetof(struct xdp_md, data_end):
			if (info->is_ldsx)
				return false;
		}
	}

	switch (off) {
@@ -9381,12 +9392,12 @@ static bool flow_dissector_is_valid_access(int off, int size,

	switch (off) {
	case bpf_ctx_range(struct __sk_buff, data):
		if (size != size_default)
		if (info->is_ldsx || size != size_default)
			return false;
		info->reg_type = PTR_TO_PACKET;
		return true;
	case bpf_ctx_range(struct __sk_buff, data_end):
		if (size != size_default)
		if (info->is_ldsx || size != size_default)
			return false;
		info->reg_type = PTR_TO_PACKET_END;
		return true;