* [PATCH v2 bpf] bpf: Fix memory leak in __lookup_instance error path
@ 2025-10-16 6:33 Shardul Bankar
2025-10-16 17:38 ` Eduard Zingerman
2025-10-16 17:40 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 3+ messages in thread
From: Shardul Bankar @ 2025-10-16 6:33 UTC (permalink / raw)
To: bpf
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Eduard Zingerman, Song Liu, Yonghong Song,
John Fastabend, KP Singh, Stanislav Fomichev, Hao Luo, Jiri Olsa,
open list, shardulsb08
When __lookup_instance() allocates a func_instance structure but fails
to allocate the must_write_set array, it returns an error without freeing
the previously allocated func_instance. This causes a memory leak of 192
bytes (sizeof(struct func_instance)) each time this error path is triggered.
Fix by freeing 'result' on must_write_set allocation failure.
Fixes: b3698c356ad9 ("bpf: callchain sensitive stack liveness tracking using CFG")
Reported-by: BPF Runtime Fuzzer (BRF)
Signed-off-by: Shardul Bankar <shardulsb08@gmail.com>
v2: Resend with complete CC list.
---
kernel/bpf/liveness.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/liveness.c b/kernel/bpf/liveness.c
index 3c611aba7f52..1e6538f59a78 100644
--- a/kernel/bpf/liveness.c
+++ b/kernel/bpf/liveness.c
@@ -195,8 +195,10 @@ static struct func_instance *__lookup_instance(struct bpf_verifier_env *env,
return ERR_PTR(-ENOMEM);
result->must_write_set = kvcalloc(subprog_sz, sizeof(*result->must_write_set),
GFP_KERNEL_ACCOUNT);
- if (!result->must_write_set)
+ if (!result->must_write_set) {
+ kvfree(result);
return ERR_PTR(-ENOMEM);
+ }
memcpy(&result->callchain, callchain, sizeof(*callchain));
result->insn_cnt = subprog_sz;
hash_add(liveness->func_instances, &result->hl_node, key);
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2 bpf] bpf: Fix memory leak in __lookup_instance error path
2025-10-16 6:33 [PATCH v2 bpf] bpf: Fix memory leak in __lookup_instance error path Shardul Bankar
@ 2025-10-16 17:38 ` Eduard Zingerman
2025-10-16 17:40 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: Eduard Zingerman @ 2025-10-16 17:38 UTC (permalink / raw)
To: Shardul Bankar, bpf
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Song Liu, Yonghong Song, John Fastabend,
KP Singh, Stanislav Fomichev, Hao Luo, Jiri Olsa, open list
On Thu, 2025-10-16 at 12:03 +0530, Shardul Bankar wrote:
> When __lookup_instance() allocates a func_instance structure but fails
> to allocate the must_write_set array, it returns an error without freeing
> the previously allocated func_instance. This causes a memory leak of 192
> bytes (sizeof(struct func_instance)) each time this error path is triggered.
>
> Fix by freeing 'result' on must_write_set allocation failure.
>
> Fixes: b3698c356ad9 ("bpf: callchain sensitive stack liveness tracking using CFG")
> Reported-by: BPF Runtime Fuzzer (BRF)
> Signed-off-by: Shardul Bankar <shardulsb08@gmail.com>
> v2: Resend with complete CC list.
> ---
Thank you for the fix!
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
[...]
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2 bpf] bpf: Fix memory leak in __lookup_instance error path
2025-10-16 6:33 [PATCH v2 bpf] bpf: Fix memory leak in __lookup_instance error path Shardul Bankar
2025-10-16 17:38 ` Eduard Zingerman
@ 2025-10-16 17:40 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2025-10-16 17:40 UTC (permalink / raw)
To: Shardul Bankar
Cc: bpf, ast, daniel, andrii, martin.lau, eddyz87, song,
yonghong.song, john.fastabend, kpsingh, sdf, haoluo, jolsa,
linux-kernel
Hello:
This patch was applied to bpf/bpf.git (master)
by Martin KaFai Lau <martin.lau@kernel.org>:
On Thu, 16 Oct 2025 12:03:30 +0530 you wrote:
> When __lookup_instance() allocates a func_instance structure but fails
> to allocate the must_write_set array, it returns an error without freeing
> the previously allocated func_instance. This causes a memory leak of 192
> bytes (sizeof(struct func_instance)) each time this error path is triggered.
>
> Fix by freeing 'result' on must_write_set allocation failure.
>
> [...]
Here is the summary with links:
- [v2,bpf] bpf: Fix memory leak in __lookup_instance error path
https://git.kernel.org/bpf/bpf/c/8adc4705e46c
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-10-16 17:40 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-10-16 6:33 [PATCH v2 bpf] bpf: Fix memory leak in __lookup_instance error path Shardul Bankar
2025-10-16 17:38 ` Eduard Zingerman
2025-10-16 17:40 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®