[PATCH bpf-next] riscv, bpf: Adjust bpf_func to account for CFI offset in bpf_jit_free

Björn Töpel bjorn at kernel.org
Thu Sep 24 08:48:36 PDT 2026


Pu Lehui <pulehui at huaweicloud.com> writes:

> From: Pu Lehui <pulehui at huawei.com>
>
> When CFI is enabled, the actual BPF program entry point is shifted
> forward by a CFI preamble. During bpf_jit_free(), this shifted pointer
> causes the wrong ro_header to be fetched, leading to a potential invalid
> memory free.
>
> Fix this by subtracting cfi_get_offset() from prog->bpf_func to
> correctly restore the original JITed allocation address before freeing.
>
> Fixes: e63985ecd226 ("bpf, riscv64/cfi: Support kCFI + BPF on riscv64")
> Signed-off-by: Pu Lehui <pulehui at huawei.com>

Reviewed-by: Björn Töpel <bjorn at kernel.org>
Acked-by: Björn Töpel <bjorn at kernel.org>



More information about the linux-riscv mailing list