On Sun, Sep 6, 2026 at 12:42 AM Jiayuan Chen <[email protected]> wrote: > > sk_protocol lives in struct sock, not in struct sock_common. A timewait > or request sock handed to bpf_sock_destroy() by the tcp iterator is > neither, so reading sk->sk_protocol runs past the object: > > ================================================================== > BUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0 > Read of size 2 at addr ffff8881047d11b4 by task test_progs/428 > > Tainted: [W]=WARN > Call Trace: > <TASK> > dump_stack_lvl+0x91/0xf0 > print_report+0xd1/0x630 > kasan_report+0xf3/0x130 > __asan_report_load2_noabort+0x14/0x30 > bpf_sock_destroy+0xc7/0xe0 > bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7 > bpf_iter_run_prog+0x538/0xde0 > bpf_iter_tcp_seq_show+0x26b/0x4b0 > bpf_seq_read+0x424/0x1210 > vfs_read+0x197/0xe40 > ksys_read+0x119/0x240 > __x64_sys_read+0x72/0xc0 > x64_sys_call+0x647/0x27e0 > do_syscall_64+0xe5/0x610 > entry_SYSCALL_64_after_hwframe+0x76/0x7e > > Only check sk_protocol on full socks. tcp_abort() already knows how to > deal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it > never matched the code. > > Fixes: 4ddbcb886268 ("bpf: Add bpf_sock_destroy kfunc") > Reported-by: Xiang Mei (Microsoft) <[email protected]> > Closes: https://lore.kernel.org/bpf/[email protected]/ > Signed-off-by: Jiayuan Chen <[email protected]>
Reviewed-by: Kuniyuki Iwashima <[email protected]>

