Re: [PATCH] arm64: bpf: Fix UBSAN misaligned access in BPF JIT
From: Fuad Tabba
Date: Wed Feb 25 2026 - 04:18:58 EST
Hi Xu,
On Wed, 25 Feb 2026 at 01:43, Xu Kuohai <xukuohai@xxxxxxxxxxxxxxx> wrote:
>
> On 2/24/2026 5:31 PM, Fuad Tabba wrote:
> > struct bpf_plt contains a u64 'target' field. The BPF JIT allocator
> > was using an alignment of 4 bytes (sizeof(u32)), which could lead
> > to the 'target' field being misaligned in the JIT buffer.
> >
> > Increase the alignment requirement to 8 bytes (sizeof(u64)) in
> > bpf_jit_binary_pack_alloc() to guarantee proper alignment for
> > struct bpf_plt.
> >
> > Fixes: b2ad54e1533e9 ("bpf, arm64: Implement bpf_arch_text_poke() for arm64")
> > Signed-off-by: Fuad Tabba <tabba@xxxxxxxxxx>
> > ---
> > arch/arm64/net/bpf_jit_comp.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
> > index 356d33c7a4ae..adf84962d579 100644
> > --- a/arch/arm64/net/bpf_jit_comp.c
> > +++ b/arch/arm64/net/bpf_jit_comp.c
> > @@ -2119,7 +2119,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_prog *prog)
> > extable_offset = round_up(prog_size + PLT_TARGET_SIZE, extable_align);
> > image_size = extable_offset + extable_size;
> > ro_header = bpf_jit_binary_pack_alloc(image_size, &ro_image_ptr,
> > - sizeof(u32), &header, &image_ptr,
> > + sizeof(u64), &header, &image_ptr,
> > jit_fill_hole);
> > if (!ro_header) {
> > prog = orig_prog;
>
> Good catch. build_plt pads NOP instructions to ensure a 64-bit relative offset for
> plt target, but it misses the alignment check for image base itself.
>
> Acked-by: Xu Kuohai <xukuohai@xxxxxxxxxxxxxxx>
>
> nit: Add check for base alignment in build_plt, or a comment to clarify?
Thanks for the having a look and for the Ack.
You're right that build_plt() assumes 64-bit alignment when
calculating the NOP padding. However, Will pointed out, over-aligning
the entire JIT buffer just to satisfy the C standard is somewhat
heavy-handed. I didn't actually run into a functional bug. The issue
is that UBSAN complains because we violate the standard's alignment
rules.
I'll dropping the allocator change in favor of marking struct bpf_plt
as __packed.
Thanks again,
/fiad