]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
bpf: fix end-of-list detection in cgroup_storage_get_next_key()
authorWeiming Shi <bestswngs@gmail.com>
Fri, 3 Apr 2026 13:29:50 +0000 (21:29 +0800)
committerAlexei Starovoitov <ast@kernel.org>
Mon, 6 Apr 2026 01:45:05 +0000 (18:45 -0700)
commit5828b9e5b272ecff7cf5d345128d3de7324117f7
tree0d6e62cec79330d4ecb64cb21bd27a80733ed1d4
parent24dbbf8a2343d4063c370a1f25645eabc50d68c9
bpf: fix end-of-list detection in cgroup_storage_get_next_key()

list_next_entry() never returns NULL -- when the current element is the
last entry it wraps to the list head via container_of(). The subsequent
NULL check is therefore dead code and get_next_key() never returns
-ENOENT for the last element, instead reading storage->key from a bogus
pointer that aliases internal map fields and copying the result to
userspace.

Replace it with list_entry_is_head() so the function correctly returns
-ENOENT when there are no more entries.

Fixes: de9cbbaadba5 ("bpf: introduce cgroup storage maps")
Reported-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com>
Acked-by: Paul Chaignon <paul.chaignon@gmail.com>
Link: https://lore.kernel.org/r/20260403132951.43533-2-bestswngs@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
kernel/bpf/local_storage.c