Re: [PATCH bpf-next] riscv, bpf: Adjust bpf_func to account for CFI offset in bpf_jit_free

From: Björn Töpel

Date: Thu Sep 24 2026 - 12:15:13 EST


Pu Lehui <pulehui@xxxxxxxxxxxxxxx> writes:

> From: Pu Lehui <pulehui@xxxxxxxxxx>
>
> When CFI is enabled, the actual BPF program entry point is shifted
> forward by a CFI preamble. During bpf_jit_free(), this shifted pointer
> causes the wrong ro_header to be fetched, leading to a potential invalid
> memory free.
>
> Fix this by subtracting cfi_get_offset() from prog->bpf_func to
> correctly restore the original JITed allocation address before freeing.
>
> Fixes: e63985ecd226 ("bpf, riscv64/cfi: Support kCFI + BPF on riscv64")
> Signed-off-by: Pu Lehui <pulehui@xxxxxxxxxx>

Reviewed-by: Björn Töpel <bjorn@xxxxxxxxxx>
Acked-by: Björn Töpel <bjorn@xxxxxxxxxx>