[PATCH v2] bpf: core: fix shift-out-of-bounds in ___bpf_prog_run

Kurt Manucredo fuzzybritches0 at gmail.com
Tue Jun 1 21:28:00 UTC 2021

On Tue, 1 Jun 2021 17:43:24 +0200, Greg KH <gregkh at linuxfoundation.org> wrote:
> On Tue, Jun 01, 2021 at 04:33:09PM +0200, Kurt Manucredo wrote:
> > Fix shift-out-of-bounds in ___bpf_prog_run().
> How is this "fixed"?
Fix shift-out-of-bounds in ___bpf_prog_run() by adding extra boundary
check in check_alu_op() in verifier.c.

> > 
> > UBSAN: shift-out-of-bounds in kernel/bpf/core.c:1414:2
> > shift exponent 248 is too large for 32-bit type 'unsigned int'
> What is this from?

> Any reason you didn't cc: the bpf maintainers and developers?
Yes. I send them to you, the mentees mailing list and Shuah, first, for
review, comment and help. Is this not okay? 

> > Reported-by: syzbot+bed360704c521841c85d at syzkaller.appspotmail.com
> Does this pass the syzbot testing?

Yes, it says 'OK' in the 'Result' column at:
It's the latest from fuzzybritches0 at gmail.com.

But at this point I cannot say if this is right. Should I send the next
version to everyone?

thanks and kind regards,

Kurt Manucredo

More information about the Linux-kernel-mentees mailing list