From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A24942EFD95 for ; Tue, 14 Oct 2025 12:01:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1760443269; cv=none; b=PtUZP8Uwx2rgs/QxabxmA/GHkO9GkXng6Tbkam6Vr72lHo1dAQL3k75KBw+ON6wZZR8r22T0kkUtYb/7G2/kIOB57r+0UMW3zbyBXdRrWjUkUJd+8fahMg2UykjgbuSZV3YttCP8OeDOgrbsOblONd8lQEcs/762HcnXfVvmXHg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1760443269; c=relaxed/simple; bh=8vcDXcnwhs3rxYjGuXzeraCiHUjPFfLkO3qyrXBdt3Q=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=XQlkDK+gwLU2VPcwQBuqb7WPg+CLHwxSkD/NX5gH8KKFsIhxGBdrFZYUUgEWIftFVnmlUyhWblyKuEMPEa5RIPCuhxMB7WsGVtQlwl1GkyXLupFlSHU1FSLD2XZYP+kdg2lpg0voL5UJVO4yGQEkdaiXWtYJ3I8TgJR92YC5hBA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=H4yH8vIn; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="H4yH8vIn" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-28e7cd34047so40886125ad.2 for ; Tue, 14 Oct 2025 05:01:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1760443267; x=1761048067; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=0yuwxDRyoAgsx6in/i8UeLI6Ei3SxN3gVvZwYXOMq/M=; b=H4yH8vInoSS83n+2nTu24/crogV1H1jYf+NUT06sV7v1ObpjJ3KJutuF5dMO2EwzYN KT37kNBCrhPYqi5S1nAwKZl7fITQySi3oj+TJtiz/MjhAWP5csiNpc9ltJGq2+/2SDCy /1YrFjT4rj+z1TEO/iAvPU48/02HY1tt2fUFHQ6uIoE6hOWpgaFJXrqL26pPPp+zZ5jO 5+OoGzTCo6tIbLHaKXYetEVx/1eVYz6d9YQGiQ1watgCNR/Ct4pJD/+n7pLtabTGFQ3s pW+7LeINrkdEDzweFiYmzQnGUelTrzKY9axpeppP8BN89zGrbl6LCRnR8bf97m/NMiIp 2xIQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1760443267; x=1761048067; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=0yuwxDRyoAgsx6in/i8UeLI6Ei3SxN3gVvZwYXOMq/M=; b=L4viEG6ooj30TB66qEk6VCPEEYy41nm2uUsKOPvGyy50pg31zcg6z6vnsXlomJsrqV r7ItjLBmqZ5EJdZ5Oy7ekcrOgQVTxM3CE2ilbRt+pzaBNN1zkuCtlxabEUuOgCbo9Anv h1VkrdkKZ6ldX4mKKLpF4AaMTrn8SyxA69/18kexT/ir3m4mI2F05kAGtu/gwQwiEuWt /p5qTwSt+/SYn1qAUAWIemGIfJQFwPPKtu0rKrXIW4oWp/qLrag+y29/iv03Bn0F3PKE Yl6XItvoyKg5zpsvHswJXgWZR1fenOTgu/SFpSFq3uX+nRkBklVyCqfRv3QjSSWNLmKy H8GA== X-Forwarded-Encrypted: i=1; AJvYcCVR04caKp0cemtDVCOYA7oZO/8ayW2pP+DEiRNGYJ7wuLO0a6y2JSXNviiU2ao5AyVH7NPB8AIKcrZaiYs=@vger.kernel.org X-Gm-Message-State: AOJu0YwBQi/ciBmJ1+Jhl0LrqDmTd4QfButgh4nV5Qco8yYKPb2vwYx9 NS1hiTq605LG3r2EfuFDsuRO5+hCDIAYDqUc5zEUI5d7RMwKLVYZyAWM X-Gm-Gg: ASbGnctnH3pslz/zm6gRW9xQFMACGZ8aXDT2Vf/O0ohmeXeLy0wb+ufNKmhu+F1ZSXu NAqkP+n+odyBcqc9jmy9R8NFbMzBjnc1gYTVOevDS4+Q1kBccpjdsICyFJ89UusVZsXcHFKKt6p AhcIi6tD6BWYBl1QHMdpd0g26GzUdGF/dcu1ela4Peyg6x3WtQKGXys/W8bSlTYZQNLPr3JeJGZ d2sV3HlTalI7+h89ZqNZydmDwZSGkp1VTR2zs20/qY3O3JiwdDc2lY43U4IyHYG4VMZAga862Gg i/0sneVzJSUpJ1f5or8uhVgK8HMXueSHohWNhbnHMGLLYJT0Z5LEllWxDcJTMW5LTfZ8tmpDAay C4Q5Moa5nusubr//xdkSAkpB5cPbYLlAEnVIex4E= X-Google-Smtp-Source: AGHT+IELofrr7ePRSX0znyiz3djLj5MGb72fhJCt3ux4kiA3yVpA6dKADS7dU33/QDcoos6p6fBzKg== X-Received: by 2002:a17:902:ebd1:b0:24c:caab:dfd2 with SMTP id d9443c01a7336-290273032a5mr308789575ad.61.1760443266446; Tue, 14 Oct 2025 05:01:06 -0700 (PDT) Received: from Shardul.. ([223.185.43.66]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-29034f3de4asm162662315ad.92.2025.10.14.05.01.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 Oct 2025 05:01:05 -0700 (PDT) From: Shardul Bankar To: bpf@vger.kernel.org Cc: Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Martin KaFai Lau , Eduard Zingerman , Song Liu , Yonghong Song , John Fastabend , KP Singh , Stanislav Fomichev , Hao Luo , Jiri Olsa , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , netdev@vger.kernel.org (open list:NETWORKING [GENERAL]), linux-kernel@vger.kernel.org (open list), Shardul Bankar Subject: [PATCH bpf 1/1] bpf: test_run: fix ctx leak in bpf_prog_test_run_xdp error path Date: Tue, 14 Oct 2025 17:30:37 +0530 Message-Id: <20251014120037.1981316-1-shardulsb08@gmail.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Fix a memory leak in bpf_prog_test_run_xdp() where the context buffer allocated by bpf_ctx_init() is not freed when the function returns early due to a data size check. On the failing path: ctx = bpf_ctx_init(...); if (kattr->test.data_size_in - meta_sz < ETH_HLEN) return -EINVAL; The early return bypasses the cleanup label that kfree()s ctx, leading to a leak detectable by kmemleak under fuzzing. Change the return to jump to the existing free_ctx label. Fixes: fe9544ed1a2e ("bpf: Support specifying linear xdp packet data size for BPF_PROG_TEST_RUN") Reported-by: BPF Runtime Fuzzer (BRF) Signed-off-by: Shardul Bankar --- net/bpf/test_run.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/net/bpf/test_run.c b/net/bpf/test_run.c index dfb03ee0bb62..1782e83de2cb 100644 --- a/net/bpf/test_run.c +++ b/net/bpf/test_run.c @@ -1269,7 +1269,7 @@ int bpf_prog_test_run_xdp(struct bpf_prog *prog, const union bpf_attr *kattr, goto free_ctx; if (kattr->test.data_size_in - meta_sz < ETH_HLEN) - return -EINVAL; + goto free_ctx; data = bpf_test_init(kattr, linear_sz, max_linear_sz, headroom, tailroom); if (IS_ERR(data)) { -- 2.34.1