| Added |
Description |
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Cancel special fields on map value recycle
Map update and delete paths currently call bpf_obj_free_fields() when a
value is being replaced or recycled. That makes field destruction depend
on the context of the update/delete operation. For tracing programs this
can include NMI context, where referenced kptr destructors, uptr
unpinning, and graph root destruction are not generally safe.
Introduce bpf_obj_cancel_fields() for the reusable-value path. It only
performs NMI-safe cleanup for timer, workqueue, and task_work fields.
Fields that need full destruction are left attached to the recycled value
and are destroyed by the final cleanup path instead.
Switch array and hashtab update/delete/recycle paths to this cancel
helper. Keep bpf_obj_free_fields() for final map destruction and for
bpf_mem_alloc destructors. Preallocated hashtabs do not have allocator
destructors, so teardown continues to walk the normal and extra elements
and fully destroy their fields.
This deliberately relaxes the eager-free semantics of map update/delete
for special fields. Programs that relied on a recycled map slot becoming
empty immediately after update/delete were relying on behavior that
cannot be implemented safely from every BPF execution context without
offloading arbitrary destructors.
There is a chance this change breaks programs making assumptions
regarding the eager freeing of fields. If so, we can relax semantics to
cancellation only when irqs_disabled() is true in the future. However,
theoretically, map values that get reused eagerly already have weaker
guarantees as parallel users can recreate freed fields before the new
element becomes visible again.
|
| Added |
Affected |
|
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/bpf.h","kernel/bpf/arraymap.c","kernel/bpf/hashtab.c","kernel/bpf/syscall.c","tools/testing/selftests/bpf/prog_tests/htab_update.c","tools/testing/selftests/bpf/prog_tests/linked_list.c","tools/testing/selftests/bpf/prog_tests/map_kptr.c","tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c","tools/testing/selftests/bpf/progs/htab_update.c","tools/testing/selftests/bpf/progs/linked_list.c","tools/testing/selftests/bpf/progs/refcounted_kptr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"14a324f6a67ef6a53e04362a70160a47eb8afffa","lessThan":"9ea734e2cc0143d7429ab7dc0b20c85e5836183c","versionType":"git","status":"affected"},{"version":"14a324f6a67ef6a53e04362a70160a47eb8afffa","lessThan":"a3a81d247651218e47153f2d2afd7aee236726fd","versionType":"git","status":"affected"},{"version":"f0462d38589422bc9e27fd3c6343dfeb6b3db2f9","versionType":"git","status":"affected"},{"version":"5.18.18","lessThan":"5.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/bpf.h","kernel/bpf/arraymap.c","kernel/bpf/hashtab.c","kernel/bpf/syscall.c","tools/testing/selftests/bpf/prog_tests/htab_update.c","tools/testing/selftests/bpf/prog_tests/linked_list.c","tools/testing/selftests/bpf/prog_tests/map_kptr.c","tools/testing/selftests/bpf/prog_tests/refcounted_kptr.c","tools/testing/selftests/bpf/progs/htab_update.c","tools/testing/selftests/bpf/progs/linked_list.c","tools/testing/selftests/bpf/progs/refcounted_kptr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
|