[PATCH bpf] bpf: Fix uninitialized known_memory read in check_mem_reg()
From: Ömer Mete Kaya
Date: Sun Sep 27 2026 - 18:33:57 EST
check_mem_reg() takes an optional bool *known_memory output parameter.
When the register is NULL, the function returns early via
mark_arg_precision() without setting *known_memory, leaving it
uninitialized.
The caller in check_func_arg() declares 'bool known_memory'
without initialization and reads it after check_mem_reg() returns:
bool known_memory;
err = check_mem_reg(..., &known_memory);
if (err < 0) {
if (known_memory)
...
}
If mark_arg_precision() returns a negative value and the register was
NULL, reading known_memory is undefined behavior. In practice only the
diagnostic message selection is affected.
Fix by setting *known_memory = false before returning in the NULL
register path, matching the intent that a NULL register does not
imply the memory region is known.
Fixes: 66e2727395dd ("bpf: Report Call Type Safety argument errors")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@xxxxxxxxx>
---
kernel/bpf/verifier.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 535967fc5f12..2cc8a2778c5a 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -7652,8 +7652,11 @@ static int check_mem_reg(struct bpf_verifier_env *env, struct bpf_reg_state *reg
{
int size, err = 0;
- if (bpf_register_is_null(reg))
+ if (bpf_register_is_null(reg)) {
+ if (known_memory)
+ *known_memory = false;
return mark_arg_precision(env, argno);
+ }
if (known_memory)
*known_memory = true;
--
2.55.0