On Tue, Aug 11, 2026 at 10:46:18AM +0800, Hui Zhu wrote: > From: Hui Zhu <[email protected]> > > This series fixes a UAF in bpf_trampoline_multi_attach_free() where > old_image is freed while ftrace still calls into it, and makes > bpf_trampoline_multi_detach() return void as suggested by Jiri Olsa. > > Patch 1 fixes the UAF. Patch 2 is an independent cleanup that > changes the return type to void and drops the WARN_ON_ONCE at the > call site. > > Changelog: > v5: > According to the comments of bot+bpf-ci, split the single patch into > two: the bug fix and the return-type cleanup. > v4: > According to the comments of bot+bpf-ci, add Fixes: and update comments > of bpf_trampoline_multi_attach_free. > v3: > According to the comments of Jiri Olsa, drop patches 2/3 and the > prog-side machinery. > keep only the simplified image-side fix in > bpf_trampoline_multi_attach_free() and make > bpf_trampoline_multi_detach() return void. > v2: > Folded v1's two detach patches into patch 1. > According to the comments of Jiri Olsa, Pin the prog (pinned_prog) on > cur_image so it stays alive while ftrace may still call into it. > Make bpf_trampoline_multi_detach() return void. > Fix the same UAF in standard (non-multi) trampolines. > According to the comments of sashiko, Fix the prog UAF in > bpf_trampoline_multi_attach() rollback. > Leak the trampoline in bpf_trampoline_put() when cur_image is left > by a rollback. > > Hui Zhu (2): > bpf: Fix UAF in bpf_trampoline_multi_attach_free on update failure > bpf: Make bpf_trampoline_multi_detach return void
Acked-by: Jiri Olsa <[email protected]> thanks, jirka
