net: filter: make JITs zero A for SKF_AD_ALU_XOR_X
The SKF_AD_ALU_XOR_X ancillary is not like the other ancillary data instructions since it XORs A with X while all the others replace A with some loaded value. All the BPF JITs fail to clear A if this is used as the first instruction in a filter. This was found using american fuzzy lop. Add a helper to determine if A needs to be cleared given the first instruction in a filter, and use this in the JITs. Except for ARM, the rest have only been compile-tested. Fixes: 34805931 ("net: filter: get rid of BPF_S_* enum") Signed-off-by:Rabin Vincent <rabin@rab.in> Acked-by:
Daniel Borkmann <daniel@iogearbox.net> Acked-by:
Alexei Starovoitov <ast@kernel.org> Signed-off-by:
David S. Miller <davem@davemloft.net>
Showing
- arch/arm/net/bpf_jit_32.c 1 addition, 15 deletionsarch/arm/net/bpf_jit_32.c
- arch/mips/net/bpf_jit.c 1 addition, 15 deletionsarch/mips/net/bpf_jit.c
- arch/powerpc/net/bpf_jit_comp.c 2 additions, 11 deletionsarch/powerpc/net/bpf_jit_comp.c
- arch/sparc/net/bpf_jit_comp.c 2 additions, 15 deletionsarch/sparc/net/bpf_jit_comp.c
- include/linux/filter.h 19 additions, 0 deletionsinclude/linux/filter.h
Loading
Please register or sign in to comment