[PATCH] bpf: Initialize IMA hash helper output buffers
From: Jiale Yao
Date: Sun Sep 27 2026 - 08:15:31 EST
The output arguments of bpf_ima_inode_hash() and bpf_ima_file_hash()
are marked as ARG_PTR_TO_UNINIT_MEM, so the verifier considers the full
range initialized after either helper returns. The IMA hash functions,
however, leave the buffer unchanged on error and only copy the digest
length on success. A BPF program can therefore read stale data from
the untouched portion of the buffer.
Clear the full destination before calling into IMA so every byte is
initialized on all return paths.
Fixes: 27672f0d280a ("bpf: Add a BPF helper for getting the IMA hash of an inode")
Fixes: 174b16946e39 ("bpf-lsm: Introduce new helper bpf_ima_file_hash()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
kernel/bpf/bpf_lsm.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
index 82c5988417a0..bc08c039dc85 100644
--- a/kernel/bpf/bpf_lsm.c
+++ b/kernel/bpf/bpf_lsm.c
@@ -168,6 +168,7 @@ static const struct bpf_func_proto bpf_bprm_opts_set_proto = {
BPF_CALL_3(bpf_ima_inode_hash, struct inode *, inode, void *, dst, u32, size)
{
+ memset(dst, 0, size);
return ima_inode_hash(inode, dst, size);
}
@@ -192,6 +193,7 @@ static const struct bpf_func_proto bpf_ima_inode_hash_proto = {
BPF_CALL_3(bpf_ima_file_hash, struct file *, file, void *, dst, u32, size)
{
+ memset(dst, 0, size);
return ima_file_hash(file, dst, size);
}
--
2.34.1