diff options
author | Edward Cree <ecree@solarflare.com> | 2017-09-15 15:37:38 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2017-09-16 00:01:32 +0200 |
commit | e67b8a685c7c984e834e3181ef4619cd7025a136 (patch) | |
tree | f6f0864ed6376f22696eee85a841e6bd38b820ec /kernel | |
parent | sctp: do not mark sk dumped when inet_sctp_diag_fill returns err (diff) | |
download | linux-e67b8a685c7c984e834e3181ef4619cd7025a136.tar.xz linux-e67b8a685c7c984e834e3181ef4619cd7025a136.zip |
bpf/verifier: reject BPF_ALU64|BPF_END
Neither ___bpf_prog_run nor the JITs accept it.
Also adds a new test case.
Fixes: 17a5267067f3 ("bpf: verifier (add verifier core)")
Signed-off-by: Edward Cree <ecree@solarflare.com>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'kernel')
-rw-r--r-- | kernel/bpf/verifier.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c index 477b6932c3c1..799b2451ef2d 100644 --- a/kernel/bpf/verifier.c +++ b/kernel/bpf/verifier.c @@ -2292,7 +2292,8 @@ static int check_alu_op(struct bpf_verifier_env *env, struct bpf_insn *insn) } } else { if (insn->src_reg != BPF_REG_0 || insn->off != 0 || - (insn->imm != 16 && insn->imm != 32 && insn->imm != 64)) { + (insn->imm != 16 && insn->imm != 32 && insn->imm != 64) || + BPF_CLASS(insn->code) == BPF_ALU64) { verbose("BPF_END uses reserved fields\n"); return -EINVAL; } |