]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
bpf: Fix off-by-one boundary validation in arena direct-value access
authorJunyoung Jang <graypanda.inzag@gmail.com>
Sun, 26 Apr 2026 17:25:05 +0000 (02:25 +0900)
committerAlexei Starovoitov <ast@kernel.org>
Sat, 9 May 2026 23:18:39 +0000 (16:18 -0700)
commit3ac1a467e37683f602221e243fa3c59b0de81165
tree6d94789f54da9f5664370898c5c5e4d56d49b4a0
parentbf6d507f7e3c65751d52fd8caf1ea4e003922624
bpf: Fix off-by-one boundary validation in arena direct-value access

BPF_MAP_TYPE_ARENA accepts BPF_PSEUDO_MAP_VALUE offsets at exactly
the end of the arena mapping (off == arena_size). The boundary check
in arena_map_direct_value_addr() uses `>` instead of `>=`, which
incorrectly allows a one-past-end pointer to be accepted.

Change the condition to `>=` to correctly reject offsets that fall
outside the valid arena user_vm range.

Fixes: 317460317a02 ("bpf: Introduce bpf_arena.")
Signed-off-by: Junyoung Jang <graypanda.inzag@gmail.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/r/20260426172505.1947915-1-graypanda.inzag@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
kernel/bpf/arena.c