Commit 6982653
bpf: Fix NULL deref in map_kptr_match_type for scalar regs
[ Upstream commit 4d0a375 ]
Commit ab6c637 ("bpf: Fix a bpf_kptr_xchg() issue with local
kptr") refactored map_kptr_match_type() to branch on btf_is_kernel()
before checking base_type(). A scalar register stored into a kptr
slot has no btf, so the btf_is_kernel(reg->btf) call dereferences
NULL.
Move the base_type() != PTR_TO_BTF_ID guard before any reg->btf
access.
Fixes: ab6c637 ("bpf: Fix a bpf_kptr_xchg() issue with local kptr")
Reported-by: Hiker Cl <clhiker365@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221372
Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com>
Acked-by: Paul Chaignon <paul.chaignon@gmail.com>
Link: https://lore.kernel.org/r/20260416-kptr_crash-v1-1-5589356584b4@meta.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>1 parent 5c04f89 commit 6982653
1 file changed
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5843 | 5843 | | |
5844 | 5844 | | |
5845 | 5845 | | |
| 5846 | + | |
| 5847 | + | |
| 5848 | + | |
5846 | 5849 | | |
5847 | 5850 | | |
5848 | 5851 | | |
| |||
5855 | 5858 | | |
5856 | 5859 | | |
5857 | 5860 | | |
5858 | | - | |
| 5861 | + | |
5859 | 5862 | | |
5860 | 5863 | | |
5861 | 5864 | | |
| |||
0 commit comments