mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf] libbpf: Fix OOB read in btf_dump_get_bitfield_value
@ 2026-01-06 23:35 Varun R Mallya
  2026-01-10  0:00 ` patchwork-bot+netdevbpf
  0 siblings, 1 reply; 2+ messages in thread
From: Varun R Mallya @ 2026-01-06 23:35 UTC (permalink / raw)
  To: andrii, alan.maguire
  Cc: ast, daniel, bpf, linux-kernel, varunrmallya, Harrison Green

When dumping bitfield data, btf_dump_get_bitfield_value() reads data
based on the underlying type's size (t->size). However, it does not
verify that the provided data buffer (data_sz) is large enough to
contain these bytes.

If btf_dump__dump_type_data() is called with a buffer smaller than
the type's size, this leads to an out-of-bounds read. This was
confirmed by AddressSanitizer in the linked issue.

Fix this by ensuring we do not read past the provided data_sz limit.

Fixes: a1d3cc3c5eca ("libbpf: Avoid use of __int128 in typed dump display")
Reported-by: Harrison Green <harrisonmichaelgreen@gmail.com>
Closes: https://github.com/libbpf/libbpf/issues/928
Suggested-by: Alan Maguire <alan.maguire@oracle.com>
Signed-off-by: Varun R Mallya <varunrmallya@gmail.com>
---
 tools/lib/bpf/btf_dump.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/tools/lib/bpf/btf_dump.c b/tools/lib/bpf/btf_dump.c
index 6388392f49a0..53c6624161d7 100644
--- a/tools/lib/bpf/btf_dump.c
+++ b/tools/lib/bpf/btf_dump.c
@@ -1762,9 +1762,18 @@ static int btf_dump_get_bitfield_value(struct btf_dump *d,
 	__u16 left_shift_bits, right_shift_bits;
 	const __u8 *bytes = data;
 	__u8 nr_copy_bits;
+	__u8 start_bit, nr_bytes;
 	__u64 num = 0;
 	int i;
 
+	/* Calculate how many bytes cover the bitfield */
+	start_bit = bits_offset % 8;
+	nr_bytes = (start_bit + bit_sz + 7) / 8;
+
+	/* Bound check */
+	if (data + nr_bytes > d->typed_dump->data_end)
+		return -E2BIG;
+
 	/* Maximum supported bitfield size is 64 bits */
 	if (t->size > 8) {
 		pr_warn("unexpected bitfield size %d\n", t->size);
-- 
2.52.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH bpf] libbpf: Fix OOB read in btf_dump_get_bitfield_value
  2026-01-06 23:35 [PATCH bpf] libbpf: Fix OOB read in btf_dump_get_bitfield_value Varun R Mallya
@ 2026-01-10  0:00 ` patchwork-bot+netdevbpf
  0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-01-10  0:00 UTC (permalink / raw)
  To: Varun R Mallya
  Cc: andrii, alan.maguire, ast, daniel, bpf, linux-kernel,
	harrisonmichaelgreen

Hello:

This patch was applied to bpf/bpf-next.git (master)
by Andrii Nakryiko <andrii@kernel.org>:

On Wed,  7 Jan 2026 05:05:27 +0530 you wrote:
> When dumping bitfield data, btf_dump_get_bitfield_value() reads data
> based on the underlying type's size (t->size). However, it does not
> verify that the provided data buffer (data_sz) is large enough to
> contain these bytes.
> 
> If btf_dump__dump_type_data() is called with a buffer smaller than
> the type's size, this leads to an out-of-bounds read. This was
> confirmed by AddressSanitizer in the linked issue.
> 
> [...]

Here is the summary with links:
  - [bpf] libbpf: Fix OOB read in btf_dump_get_bitfield_value
    https://git.kernel.org/bpf/bpf-next/c/5714ca8cba5e

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-01-10  0:03 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-01-06 23:35 [PATCH bpf] libbpf: Fix OOB read in btf_dump_get_bitfield_value Varun R Mallya
2026-01-10  0:00 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®