Commit bc354886 authored by Alexei Starovoitov's avatar Alexei Starovoitov Committed by Greg Kroah-Hartman

bpf/verifier: disallow pointer subtraction

commit dd066823 upstream.

Subtraction of pointers was accidentally allowed for unpriv programs
by commit 82abbf8d. Revert that part of commit.

Fixes: 82abbf8d ("bpf: do not allow root to mangle valid pointers")
Reported-by: 's avatarJann Horn <>
Acked-by: 's avatarDaniel Borkmann <>
Signed-off-by: 's avatarAlexei Starovoitov <>
Signed-off-by: 's avatarDaniel Borkmann <>
Signed-off-by: 's avatarGreg Kroah-Hartman <>
parent 909828a2
......@@ -3132,7 +3132,7 @@ static int adjust_reg_min_max_vals(struct bpf_verifier_env *env,
* an arbitrary scalar. Disallow all math except
* pointer subtraction
if (opcode == BPF_SUB){
if (opcode == BPF_SUB && env->allow_ptr_leaks) {
mark_reg_unknown(env, regs, insn->dst_reg);
return 0;
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment