Files
linux-stable-mirror/kernel
Bradley MorganandGreg Kroah-Hartman aa265d4730 bpf: Disable xfrm_decode_session hook attachment
[ Upstream commit 12091470c6 ]

BPF LSM programs can currently attach to xfrm_decode_session(). That
hook may return an error, but security_skb_classify_flow() calls it
from a void path and triggers BUG_ON() if an error is returned.

Disable BPF attachment to the hook to prevent a BPF LSM program from
turning packet classification into a full panic.

Fixes: 9e4e01dfd3 ("bpf: lsm: Implement attach, detach and execution")
Signed-off-by: Bradley Morgan <include@grrlz.net>
Link: https://lore.kernel.org/r/20260619130305.27779-1-include@grrlz.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2026-07-24 15:54:52 +02:00
..
2025-12-07 06:12:35 +09:00
2023-12-20 17:00:20 +01:00
2023-11-28 17:06:57 +00:00
2024-10-17 15:22:28 +02:00