From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 30AE239099E for ; Sun, 14 Jun 2026 09:26:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781429190; cv=none; b=AjmhQkHj6TEDcpnzl4oaPUYLHVxfANWboAHCPnd0jY0z0SDKdxjyWNHKiPsptwLAt2CKjOHQ7Zqr5H5VOPEbLaAhTnB40wJp9znxHtP1DNk6hcuCMdCzXIDtqYTUAJ4+u38wXPNIMFn9MOgYMHt9Q0yPOBT7Z7TsYxX8pcDwEsk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781429190; c=relaxed/simple; bh=tl1gbtf86a0S1llqs4X38XTvX69cB6KA93mt/uCE6DU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=iVHS8tIqlEdantqhQkiBwNkaaufUtGAuozXBlZ91pjebQAmQAQlM+FZYoSSq3qiJInQgEDZn+7fqT6jdw6FsFinQUKfWSIS3FnPJhPJKzzBc3w9Q7bZ61hqg0qpe4aX5TwGWZqTu3mGalq8D8CC88iu5cU7Ov3CbboK3TA+SXBQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nJxYLBHY; arc=none smtp.client-ip=209.85.215.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nJxYLBHY" Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-c86214eead7so969424a12.0 for ; Sun, 14 Jun 2026 02:26:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781429186; x=1782033986; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=d16k0vZR1zettaTdZ3HXP0MjQdOsOHiGY8GKp79+E2s=; b=nJxYLBHYRr6bFb4koagSWnjAp6lTGLoCkFZJzRsoGSN1dT/1xDST6P72Y1rS4BBU1c /ksxdMoKaCFg7E2lOuTSwgDuOs6h1YkOhakArzUIdQhtTBByERozUohhr7mfOfEoK7V3 0BNzn6CPonQ3WFkv9POg3+TS9a74S1jnU8jXget7Q/XfKXKB5fJF7gfxbzyKzHmUhM1N R6ZE6pHoq8UBJg7x3oKdcUGTC/PT+CgeJMPR+uJOwU3hed2+5CtwSPacXHBCSgsHlQpX r7Xcbi3hM8aZAYTYNTSbZJINtEu8SzEz1SFviVZmgUcrsQKTI/q59ows+4fRtb87EyMc RjWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781429186; x=1782033986; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=d16k0vZR1zettaTdZ3HXP0MjQdOsOHiGY8GKp79+E2s=; b=FufndOmcGtDz2eMMJ9UF+UUc5I8JXddyRhyh9hXN42AMzMi13R0jxbkFqW+RmB6m0j 6Kaac8ofsEkOk2SPIark2ipTPKteamrk/vmtXxX3jC0uuNJUt7P8PmvdvwJCoIH78glj vRZhCWf/4zAx6AsAWuIcT45ylsN8YaNqRJVE/3wHJ5KYkHL0KikXu+s5Ra8R/foE3smr ohzVGrBwUMEJIw0G3Kh0rg6IIGP/wAbJBEIoknKg425qNlUVWInIQ3hXI5QYm6mXYuZU LMhm2CBbtUTumyj+p8vRrFBUD8FLXlqYKGBNyr9YV5ERjg+MvFUDhAVTDfHrV+dF31GM GApQ== X-Forwarded-Encrypted: i=1; AFNElJ+F49stjDyfMQmZkGS+hGbFE23y4ahQhblAlD8ZMlHpMIC+4jZRty2m99E+Meghmd9Nq/7X7beXSzN5Mlk=@vger.kernel.org X-Gm-Message-State: AOJu0Yy0+jPpctRfOD+4dGVNn3Jp/kmCGpBJrNFM3w904cU1BmSQSByV u81X8faSiA6NOHLO6jbCu6swQyNUqvckjBik50/zuN5AFRanK+G0Vbuy X-Gm-Gg: Acq92OG0AE2HRXIurWhhtxsaWgTF+HpqTpdlOPdGYWSfMv2ZdqDMJPJxPrLhskBC+QI jaQ/NwMpusIf3qgKXA0GxCZgWyctq/lxvq8InWWUjdsMbpphUSbJELIh63HfEKo2nBF0L6ksYKe ImrNFigtNm92EPm8Tea/JZz9cgx5eqYB8KFRRMgfR0lY2qoNCPpa3aRIlHlY7ipaEul8KxOThrR f05/RmH1pjwlWU/2r8yRXp4c8yakW4nJCqaCGpKUqMiTf7NvbEijh7HCRDDaRCWYa1VJPe+70P1 dh9RcqLQ+cA63iqtgkwRMVYednH6CvTFVQWmeLqhB0x00u0coymJB3fnerlFvg15mgZmXgkV1ro oXHWb+LpTslCFbf/tkcbBVoHizvIase4HdCy+XDiQc3jqMjkvwv61Kq/ebuEx6LqLxiH/Mv7vx4 77xmyBqN1h4JFdypg/GHdvMdheyT1yIdMc9/fyQrjmKEG6ZxcOBf7hYwQ2JIQuf9a0gAmdpd0Gx LFX6v+caYGH4MXL X-Received: by 2002:a05:6a21:9207:b0:3b5:530d:d96d with SMTP id adf61e73a8af0-3b7857de1b2mr8737610637.12.1781429186348; Sun, 14 Jun 2026 02:26:26 -0700 (PDT) Received: from nugod-NUC15CRHU5.tail9f095a.ts.net ([218.237.104.87]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8434b057461sm8198423b3a.58.2026.06.14.02.26.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 14 Jun 2026 02:26:25 -0700 (PDT) From: HyeongJun An To: Andrii Nakryiko , Alexei Starovoitov , Daniel Borkmann Cc: Eduard Zingerman , Kumar Kartikeya Dwivedi , Martin KaFai Lau , Song Liu , Yonghong Song , Jiri Olsa , Shuah Khan , bpf@vger.kernel.org, linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org, HyeongJun An Subject: [PATCH bpf v2 0/2] libbpf: Reject out-of-range linker relocation offsets Date: Sun, 14 Jun 2026 18:26:14 +0900 Message-ID: <20260614092616.165337-1-sammiee5311@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The libbpf static linker validates relocation type, symbol index and instruction alignment in linker_sanity_check_elf_relos(), but does not check that the relocation offset is inside the relocated section. A malformed BPF object processed by the static linker (e.g. via "bpftool gen object") can therefore carry an out-of-range r_offset that linker_append_elf_relos() then uses to index the section data, reading and writing past the buffer. The normal object-loading path already rejects such offsets (libbpf.c, rel->r_offset >= scn_data->d_size); the static linker path is the missing sibling. Patch 1 adds the same bound. Patch 2 adds a selftest that builds a tiny object with an out-of-range relocation offset and checks that the linker now rejects it, with a valid relocation as a positive control. Reproduced with ASAN: before patch 1 the out-of-range relocation is accepted (and triggers a heap-buffer-overflow); after, it is rejected with -EINVAL. Changes in v2: - selftest: set the generated ELF object's EI_DATA from the host byte order instead of hardcoding little-endian, so it works on big-endian hosts (e.g. s390x). - selftest: add fallback definitions for EM_BPF and R_BPF_64_64 for older system headers. Patch 1 (the fix) is unchanged. HyeongJun An (2): libbpf: Reject out-of-range linker relocation offsets selftests/bpf: Test linker rejects out-of-range relocation offset tools/lib/bpf/linker.c | 6 + .../selftests/bpf/prog_tests/libbpf_linker.c | 231 ++++++++++++++++++ 2 files changed, 237 insertions(+) create mode 100644 tools/testing/selftests/bpf/prog_tests/libbpf_linker.c -- 2.43.0