From nobody Fri Oct 2 10:07:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AC7AC377AB5; Sun, 2 Aug 2026 14:27:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680847; cv=none; b=W8TEHaXowGZBQP6QwairgsjIcDn54qQ9sbqnlpbfRUVglp71MgwCx+cYDEDgW4/39pAtG23cUFop+KE8gzwZSeWueezxOoBw6tECXvDVZtghW80teDpbGGixzZbi1SAMog75ri/ONnjwdMNWXQThQ+UwbS7Fk6gNIYj8Kwr+qsE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680847; c=relaxed/simple; bh=YkWJsw1x92FJoCNdCuRVMvI1nFCwL9eILPzavWcg+7M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=owZF/aLM6nxbqxHDGzWuknurg5jTb2w9GQ+hXlMV6Xb3Dfh98hPJn4zbBTi43yZuObq2mE+OwtIkx+UWvaRw55huMtKpa6o5flWkoamAod7IFFxOVWHxGpQN0Iou81PfBZjLVyCkEZZXScCdzOt7KMWA8xbTqB2yLmvOyJ8SxjI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Q9QWNc4T; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Q9QWNc4T" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3BF101F000E9; Sun, 2 Aug 2026 14:27:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785680846; bh=KZRceK2vwHkMBIIeSH1tpa2/APit2uWHTO9BMVPtBwc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Q9QWNc4Tom35CBhzTtOBMXx1PJVgCs+DeP39JTw44Ns35p5eGzd/QICUWMKKmPLWs /y+JkeSCJomBht77e17yvU9TxYulounGqD7Y76HxYQWS064EHS5P1Uuo+96K64oNKF 90T+KjOjHYsxtSSfXLKVnY0zsphEbpKINutH3hiuTgYot173EFJ4vv2uwg9TdrUdNv AOcdh0L06N14gcpl5NsLdo5Hxz3NlbvB1dDuJSIWL5Os4RpBwrh94p29zTeoutaQTY Q5Y5qmT5UMTEOTxHYLrzXDdH0FewW3wecIDojs5fIXjDT9iIS2oIGUlTnkvkAVJfGi YpYIS19b6CBYA== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Song Liu Subject: [PATCH 1/4] perf libbfd: Validate BPF prog info arrays before pointer cast Date: Sun, 2 Aug 2026 11:27:09 -0300 Message-ID: <20260802142712.154726-2-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802142712.154726-1-acme@kernel.org> References: <20260802142712.154726-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo symbol__disassemble_bpf_libbfd() casts info_linear->info.jited_prog_insns and info_linear->info.jited_ksyms to pointers without checking whether bpil_offs_to_addr() actually converted the file offsets. A crafted perf.data with PERF_BPIL_* bits unset but non-zero counts causes raw file offsets to be dereferenced as pointers. Add bitmask checks for PERF_BPIL_JITED_INSNS and PERF_BPIL_JITED_KSYMS before the casts, matching the validation added to bpf-event.c call sites. Fixes: 6987561c9e86 ("perf annotate: Enable annotation of BPF programs") Reported-by: sashiko-bot Cc: Song Liu Cc: Ian Rogers Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/libbfd.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/tools/perf/util/libbfd.c b/tools/perf/util/libbfd.c index d8241c7caac50836..0b7164f0e9fdbbed 100644 --- a/tools/perf/util/libbfd.c +++ b/tools/perf/util/libbfd.c @@ -552,6 +552,11 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym = __maybe_unused, info_linear =3D info_node->info_linear; sub_id =3D dso__bpf_prog(dso)->sub_id; =20 + /* jited_prog_insns is only valid if bpil_offs_to_addr() converted it */ + if (!(info_linear->arrays & (1UL << PERF_BPIL_JITED_INSNS))) { + ret =3D SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF; + goto out; + } info.buffer =3D (void *)(uintptr_t)(info_linear->info.jited_prog_insns); info.buffer_length =3D info_linear->info.jited_prog_len; =20 @@ -581,6 +586,12 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym = __maybe_unused, if (disassemble =3D=3D NULL) abort(); =20 + /* jited_ksyms is only valid if bpil_offs_to_addr() converted it */ + if (!(info_linear->arrays & (1UL << PERF_BPIL_JITED_KSYMS))) { + ret =3D SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF; + goto out; + } + fflush(s); do { const struct bpf_line_info *linfo =3D NULL; --=20 2.55.0 From nobody Fri Oct 2 10:07:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CAB04377AB5; Sun, 2 Aug 2026 14:27:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680851; cv=none; b=FaXxG3Avoyh4/lb6Bb1ZZh4Gy2qkStU2HYfro9UOwTZ3bh1MdG2+191GzaASOYkhdUR1x4ZsXI4ifXNt3zz5iosCoyhI5p+BRZV+R/Syc5DTSTr/0nyA15ziu4GB0l+JgT9qk1BZ6M0GDX0NBbywkAA/Pj7ShcQ68rZYlilC4LE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680851; c=relaxed/simple; bh=DR6PD7Ey5TmqTWgHBew+d145z/STPQJ/kBWViIfNl/U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pvVpg/XmM/dT6AQPHd5HuRnEsVpRfrfVUCUWVxcc3vVpuDXksHMDbLBf8yIQr7akxX3XcDAJRYv18znQ9WrarlwYJg/QBnhSGV9BcsVlFOd17IAScxPhlC/rZtjb2MTp46WA1GdD64ANdV8hBTGHNsx8TNLGLD4L9EUQkGXfST4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=mtzEWc4N; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="mtzEWc4N" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1E4C71F00A3A; Sun, 2 Aug 2026 14:27:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785680850; bh=iLiBwdShXAbqRqFRhrLT845rNT8E4xpqJqX8bz89zqg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mtzEWc4NZKNDvefcrCdZ32sBCiqSZEgBiMuaOriQaDMXpXfzbqJL5GgxN9tipzz8s SKCA6lzkPz1ODixtZz/UsoCtqWBzRiYvy20QF/nsdjj3ZNqFvIcNY0bz1lbXircXtF H7rHv+eLzP+8VVydocA8OOzxpGg/GczTfrCsHjgPx0GNpyWhv9OL8wanECE9pNnFou F7hKuflflLiLqN+1/1u/rZsLsGARXoGblKx/Lr+1nVcotbjHAeqBV8lM6HU46qVVxl VYrk7wff996ISb51wHiU6McIaB/THIyTrxDg9OYiSN7c1Q/h34SVvpe0stLb15Ki2I vmKY7HFfktJuw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Song Liu Subject: [PATCH 2/4] perf header: Use write lock when translating BPF prog info pointers Date: Sun, 2 Aug 2026 11:27:10 -0300 Message-ID: <20260802142712.154726-3-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802142712.154726-1-acme@kernel.org> References: <20260802142712.154726-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo write_bpf_prog_info() holds a read lock while temporarily mutating info_linear via bpil_addr_to_offs()/bpil_offs_to_addr(). Between these two calls, the pointers in info_linear contain file offsets instead of heap addresses. Concurrent readers holding the same read lock see the file offsets and dereference them as pointers. Use down_write()/up_write() instead of down_read()/up_read() to exclude concurrent readers during the addr-to-offset-to-addr translation window. Fixes: 63ac7968a1fb ("perf bpf: Save bpf_prog_info information as headers t= o perf.data") Reported-by: sashiko-bot Cc: Song Liu Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/header.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/header.c b/tools/perf/util/header.c index e90e541f546b4537..7db7da090a1e0c78 100644 --- a/tools/perf/util/header.c +++ b/tools/perf/util/header.c @@ -1120,7 +1120,8 @@ static int write_bpf_prog_info(struct feat_fd *ff __= maybe_unused, struct rb_node *next; int ret =3D 0; =20 - down_read(&env->bpf_progs.lock); + /* write lock: bpil_addr_to_offs() temporarily mutates info_linear */ + down_write(&env->bpf_progs.lock); =20 ret =3D do_write(ff, &env->bpf_progs.infos_cnt, sizeof(env->bpf_progs.infos_cnt)); @@ -1150,7 +1151,7 @@ static int write_bpf_prog_info(struct feat_fd *ff __= maybe_unused, goto out; } out: - up_read(&env->bpf_progs.lock); + up_write(&env->bpf_progs.lock); return ret; #else pr_err("ERROR: Trying to write bpf_prog_info without libbpf support.\n"); --=20 2.55.0 From nobody Fri Oct 2 10:07:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B10A83B3BF2; Sun, 2 Aug 2026 14:27:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680855; cv=none; b=g3/+mxJrrXwMlJMypVO5BkeS+NPc0yRC9koRzf7IDpF/AA/g6zNA+RYqazxVSeVpcMXp1jsTn6DnRLl/u+2wGkBzWJyqpuECOiBWBZQPW8/tdT0whUgHdNGf+LE8UxhmfaNgBIe25oYvTmc9hmQD5/fyrHcAr8by/2km+McYDU0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680855; c=relaxed/simple; bh=x0unN/UQx+AgsfupzIsukpdZ6hVjrnR2Yb7n+UW85dE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ei3bgbEqqCzqPLytw/h2h7GYU2hmWGIZWhJgfWjn0hkLjTL16oCTi3J3ckfDdaGB/m6aEquyPNzPKY8OkeBs6iZgm32T89wYap6otH4HfR1VyZ/QYocCyu9bn6qnvgK1HjjwhNQQ4CixrxUQDB+8Cy3FHPolFsU+lVwc1y95KMY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Avj2MTpE; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Avj2MTpE" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 008001F000E9; Sun, 2 Aug 2026 14:27:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785680854; bh=RiCwrxeVEM+TddSPFLmqOr/uymJkz7tQ39k0YA6dst8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Avj2MTpErXHcGwYyRC+KCF9G9VW2bK7ObLbK7bXX6HDPUUiZw71tbQIL/vECYT21E AIOL5G3/mCipwutqrSLbcCW6mu+uEoHRS69Pa5U5Pa/5JXLWTs9FOfvy4WS2jpT9mU WHblG9xlMmJ06pTbYagd8rbXwwfxuO2RxBdUcEyNNCYsS2dTKto6yjJNmFYaoKrS85 SSVpFcklJutYq/vCE7xOGF4xpbLnNCcuQtyVQquyJ/caGpMcfx3xQMAwZZIHcKCGGR 3mVPJcMfsTJ+VIAByb+myxR9YLbjeu34WkUD0bMGecak0xmaoVwOsdlL/3yiv7/YH7 CDu/xdeeOSRrw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Song Liu Subject: [PATCH 3/4] perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info() Date: Sun, 2 Aug 2026 11:27:11 -0300 Message-ID: <20260802142712.154726-4-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802142712.154726-1-acme@kernel.org> References: <20260802142712.154726-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo synthesize_bpf_prog_name() unconditionally dereferences prog_tags[sub_id] (line: u8 (*prog_tags)[BPF_TAG_SIZE] =3D (void *)(uintptr_t)(info->prog_tag= s)) but __bpf_event__print_bpf_prog_info() only requires JITED_KSYMS and JITED_FUNC_LENS in its required_arrays bitmask. If a crafted perf.data has the PROG_TAGS bit cleared (or the array was invalidated by bpil_offs_to_addr() bounds checking), info->prog_tags contains either zero or a raw file offset. Dereferencing it causes a NULL pointer dereference or an arbitrary memory read. Add PERF_BPIL_PROG_TAGS to required_arrays so the function returns early when prog_tags was not present or failed validation. Fixes: f8dfeae009effc0b ("perf bpf: Show more BPF program info in print_bpf= _prog_info()") Reported-by: sashiko-bot Cc: Song Liu Cc: Ian Rogers Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/bpf-event.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/bpf-event.c b/tools/perf/util/bpf-event.c index fa3ebc8ea7f09cdd..e67f28a8e92bdeb0 100644 --- a/tools/perf/util/bpf-event.c +++ b/tools/perf/util/bpf-event.c @@ -969,7 +969,8 @@ void __bpf_event__print_bpf_prog_info(struct perf_bpil = *info_linear, { struct bpf_prog_info *info =3D &info_linear->info; __u64 required_arrays =3D (1UL << PERF_BPIL_JITED_KSYMS) | - (1UL << PERF_BPIL_JITED_FUNC_LENS); + (1UL << PERF_BPIL_JITED_FUNC_LENS) | + (1UL << PERF_BPIL_PROG_TAGS); __u32 *prog_lens; __u64 *prog_addrs; char name[KSYM_NAME_LEN]; --=20 2.55.0 From nobody Fri Oct 2 10:07:35 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A2BD23BBFA7; Sun, 2 Aug 2026 14:27:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680859; cv=none; b=JtKqfGsV2zcv8nR1vxlY5Jm3wEzhKxAwW3DoKGjrUFqJ2jJOOKX/beckbB0JZuG9vR6F+VupQjhnmcR86FZT1jb9tj/sERz0E3hSyXjvRhg8D+8kswpwN7vlL/DaDQkly+O802sPpQY4UXPyrJhTHM3u3U4ekK76I4tfUIaTmQw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785680859; c=relaxed/simple; bh=RssS8yXWgi99ltQFt5HsQBN1pUKisoH39b+GInwBNs8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Es+pCas/W11ebkmmR00yI/PwVQ4Nn9yxahj6Jy15SKKvE2cDXweaTTWHICBrzOD651EamOb0cYbUhXEFx04GziXD300OwgXpuOws0i0Hkc1YsbK1p6gZ4PmsUXYDXxZKZvpla+MkM/00VCP/+3O0c9BQsyV9fdl762OhdJxY0rU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=neEzol0W; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="neEzol0W" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D70501F00A3A; Sun, 2 Aug 2026 14:27:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785680858; bh=UMPFYv9gvFZQWW2DITLYJDCibDQw6FEHiT9noD/oGKg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=neEzol0WquA+aw9hSQ1vQNboZocNjacwd1T9m0VoYpKQ1ER9bCYXh/wDnCPebK+T3 McQ13L8VuGDqA8Pk1wJQNgwKY+ReBljglk5tuQUiQFU8uXl4/QnIli1ZcklycfgO6V E4ajHnKux5EEj9r09w51gJTTiqT69VItmRIksE7UnEgTUP0eE0wD3H33+vwRSg+bpy cG299zS/HMOKF2IccIh8uNKT+mcdGMyzbc4rjKZrCH4z0vpQKtDzeyvRUJPehLrrvk DZxQhvf+vdZiK7inVNRXKm4ejVbxS8ze2Ez3yWaIK+6/7OinJO/f/AtETCdSh7mkul yYsnVyRUBgMGg== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Song Liu Subject: [PATCH 4/4] perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly Date: Sun, 2 Aug 2026 11:27:12 -0300 Message-ID: <20260802142712.154726-5-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260802142712.154726-1-acme@kernel.org> References: <20260802142712.154726-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo symbol__disassemble_bpf_libbfd() has four resource management bugs: 1. free(prog_linfo) leaks internal arrays. bpf_prog_linfo contains raw_linfo, raw_jited_linfo, nr_jited_linfo_per_func, and jited_linfo_func_idx pointers that are only freed by the proper destructor bpf_prog_linfo__free(). 2. open_memstream(&buf, &buf_size) allocates a dynamic buffer that the caller must free after fclose(). The function calls fclose(s) but never free(buf), leaking the stream buffer on every call. 3. args->line =3D strdup(srcline) is immediately consumed by disasm_line__new(args) which internally calls strdup(args->line) again via annotation_line__init(). The first strdup result is then overwritten by args->line =3D buf + prev_buf_size without being freed. 4. If open_memstream() fails, the error path jumps to 'out:' which calls fclose(s) with s =3D=3D NULL =E2=80=94 undefined behavior. Fix by using bpf_prog_linfo__free(), initializing buf to NULL, adding free(buf) after fclose(s), guarding fclose() against NULL, and removing the redundant strdup since annotation_line__init() makes its own copy. Fixes: 6987561c9e86eace ("perf annotate: Enable annotation of BPF programs") Reported-by: sashiko-bot Cc: Song Liu Cc: Ian Rogers Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/libbfd.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/tools/perf/util/libbfd.c b/tools/perf/util/libbfd.c index 0b7164f0e9fdbbed..33dc6158b2b1ffab 100644 --- a/tools/perf/util/libbfd.c +++ b/tools/perf/util/libbfd.c @@ -15,6 +15,7 @@ #ifdef HAVE_LIBBPF_SUPPORT #include #include +#include #endif #include #include @@ -510,7 +511,7 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym _= _maybe_unused, char tpath[PATH_MAX]; size_t buf_size; int nr_skip =3D 0; - char *buf; + char *buf =3D NULL; bfd *bfdf; int ret; FILE *s; @@ -620,7 +621,7 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym _= _maybe_unused, =20 if (!annotate_opts.hide_src_code && srcline) { args->offset =3D -1; - args->line =3D strdup(srcline); + args->line =3D (char *)srcline; args->line_nr =3D 0; args->fileloc =3D NULL; args->ms->sym =3D sym; @@ -645,9 +646,12 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym = __maybe_unused, =20 ret =3D 0; out: - free(prog_linfo); + bpf_prog_linfo__free(prog_linfo); btf__free(btf); - fclose(s); + if (s) { + fclose(s); + free(buf); + } bfd_close(bfdf); return ret; #else --=20 2.55.0