From: Andrii Nakryiko Date: Mon, 25 Oct 2021 22:45:28 +0000 (-0700) Subject: libbpf: Fix off-by-one bug in bpf_core_apply_relo() X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=b5949ef0753be9b560482b8e6b9305c62c6d7830;p=linux.git libbpf: Fix off-by-one bug in bpf_core_apply_relo() [ Upstream commit de5d0dcef602de39070c31c7e56c58249c56ba37 ] Fix instruction index validity check which has off-by-one error. Fixes: 3ee4f5335511 ("libbpf: Split bpf_core_apply_relo() into bpf_program independent helper.") Signed-off-by: Andrii Nakryiko Signed-off-by: Alexei Starovoitov Link: https://lore.kernel.org/bpf/20211025224531.1088894-2-andrii@kernel.org Signed-off-by: Sasha Levin --- diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c index 51180f300d2e1..7145463a4a562 100644 --- a/tools/lib/bpf/libbpf.c +++ b/tools/lib/bpf/libbpf.c @@ -5138,7 +5138,7 @@ static int bpf_core_apply_relo(struct bpf_program *prog, * relocated, so it's enough to just subtract in-section offset */ insn_idx = insn_idx - prog->sec_insn_off; - if (insn_idx > prog->insns_cnt) + if (insn_idx >= prog->insns_cnt) return -EINVAL; insn = &prog->insns[insn_idx];