From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B85FE41A54B; Wed, 5 Aug 2026 13:31:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936680; cv=none; b=iyD8N/YqIoPSkBTjWOM1rTcxQCHo0PsYfbFuD3uO40N38+7oGa2aGbcv1PhzcTA5/iLudVBoRImfUt1+B9d4fWH2BsPuYzq32jiYMwk1yBJzU/TTial0khJDXaZGPPJt4rCKaHB7GJSuus5fXeooSklne9QwuWR2s97p6CepxNM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936680; c=relaxed/simple; bh=fRGmXGaHb5SpkLn0+AAs910q+lB7cz0Fp22es0fXd1U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Kza40UW8Nm0LGa0+RueK8RXuB6QkpfBI/5T2V9+o6fwK4QVt/VOWU/65tqAiWr7uGSY8xhRrbT4bO0xW3tN4JHm2IRW7VBnfVuOEe4Etk9PMGCkyBrDC0YmUPFG/azbBIu0aRq2Ge1vk270CLMVol1120OB5st+On9JhaztCjmk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=MedekOzG; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="MedekOzG" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B173B1F00A3A; Wed, 5 Aug 2026 13:31:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936679; bh=e1Q0ojvl+8bO5DnzYd6w7JYVX4ZMv2eI74LKEXp7g80=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MedekOzGd3ThSSD4/8Ck+oDqVMjsa8EMT8Y7PyM9vy7ooTLGIuvBold0WDT0HlwKp kQDnZIdLlAeMVT9yLEQNkWRNYD3EbhfaZQ4WJU7fFSTsI+2jRUwFYtE1zGIgEVBfSe 9n+nfvhFsLW20ErKTEbiS7lrBTZ7drRiYGTTm+pPfrX96nzCqNIDII4EU5okfD63ea o3+qpeMQiPyUnZsL1AvCpeDWPRWgSLWFXNB4uu7arPP9dGAWYMCQvZEojc/9FIrhec 8enPA8D2Bf9tyrAT8Cyh0rsObTGsPWkCS5U9aF6rKOQW/pUvN1uWFduDuq2eDi14tC HAxPwRdsPscsQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 01/12] perf jitdump: Fix extended header read that always fails Date: Wed, 5 Aug 2026 10:30:00 -0300 Message-ID: <20260805133013.235016-2-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_open() sets bsz =3D bs before the fread() that uses bs - bsz as the read size, making the expression always evaluate to zero. fread() with size 0 returns 0, which triggers the ret !=3D 1 error path =E2=80=94 so ext= ended jitdump headers (total_size > sizeof(header)) have been silently broken since the original implementation. Additionally, when 0 < bs <=3D bsz the if (bs > bsz) block is skipped entirely, leaving extended header bytes unread in the stream. Subsequent jit_get_next_entry() calls then parse those leftover bytes as a jr_prefix, corrupting the record stream. Fix by separating the buffer growth from the read: realloc only when bs > bsz, then unconditionally fread bs bytes when bs > 0. Fixes: 9b07e27f88b9cd78 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Cc: Ian Rogers Cc: Namhyung Kim Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 83005b30b9bf3fd7..4b7c7ba7cd95ddbb 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -224,10 +224,12 @@ jit_open(struct jit_buf_desc *jd, const char *name) n =3D realloc(buf, bs); if (!n) goto error; - bsz =3D bs; buf =3D n; - /* read extra we do not know about */ - ret =3D fread(buf, bs - bsz, 1, jd->in); + bsz =3D bs; + } + if (bs > 0) { + /* consume extended header bytes from the stream */ + ret =3D fread(buf, bs, 1, jd->in); if (ret !=3D 1) goto error; } --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 905FA471246; Wed, 5 Aug 2026 13:31:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936685; cv=none; b=bn82dmDw9Ul+nGdD3AJ/ZG6J7rNjuCqmz7+YE2yFHw4VhwePLDOoA8JM0iDlvvW0LZcicq/Fu8ZpBDqo2W3QczGdA93AWFFJdFwmo+htGmZn2VnQiPQTV0JpVuMtakp7IYb6reX8PlQPMUYIQc4SCAHmlZAtkXjOrVaAdkZeWCw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936685; c=relaxed/simple; bh=bxkbjvjH3PR73oWSLczuqdxQFZY0bWmOlSKjeaRTDKQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=H4frXurtVbUFAVAezj9FiS8pIDgS1NneDGGeDda6drYXdixZgz64wA2FatuP3svxZdmXpe99fGx4MyVB4TWdE7TmJxog5/HHCw3jfmryHQtki26X2yXzb+D00RUCbpTkckFmTl2tIUdAajf4PVEnVj65i5POMj31FpH8MrfVYZ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=eCF6iOje; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="eCF6iOje" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0CC951F000E9; Wed, 5 Aug 2026 13:31:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936684; bh=5hNEFcTuONvGHX51AFIg3nJnFMlGn8L15Q3WLQ6IMws=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=eCF6iOje+7bIyb17Oubd+7v2/vTz4hEAuJ8dbVnwavwf4BfcRRzNEMJX6ooPk3bAE 8hTUBtMNUDrSMkNtCRc78ieYaLd7+kT7NSg/kM73cpYAQwqOQOLgcPD9q9DM4ED9mg JIRoeckltsvlwnydTKtOIwLt7eqMG1x8pOTc9YTSfdWKtwErE6lHjDFsgz4o9GDntw MTEcKoGeOL54SbOBDe5PlbtEO7L1EJLpsIKlARHHHl5D0Pngy8Yoiep2v0zcClMFJJ kcxNKoq+2Bt2eCy9I31pKG6/wyo1edHSvIxgLEFAEUmlVJ5jeVL2M7etT5jJwgsIlS SVm6l1ShLbkYQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 02/12] perf jitdump: Validate code_size against total_size in code load Date: Wed, 5 Aug 2026 10:30:01 -0300 Message-ID: <20260805133013.235016-3-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo jit_repipe_code_load() reads code_size from the jitdump record and uses it to compute a pointer to the code blob: code =3D (unsigned long)jr + jr->load.p.total_size - csize; An oversized code_size underflows the pointer arithmetic, causing OOB reads into earlier heap memory. Validate that code_size fits within the record (total_size - sizeof(jr->load)) before the pointer computation. code_size is uint64_t but csize is int; values above INT_MAX wrap negative when narrowed into csize, which defeats the bounds check and sends the code pointer past the end of the record. Reject those too. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Assisted-by: Opencode:mimo-v2.5-free Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 4b7c7ba7cd95ddbb..3195f94187164066 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -9,6 +9,7 @@ #include #include #include +#include #include #include #include @@ -450,6 +451,16 @@ static int jit_repipe_code_load(struct jit_buf_desc *j= d, union jr_entry *jr) csize =3D jr->load.code_size; usize =3D jd->unwinding_mapped_size; addr =3D jr->load.code_addr; + + /* code blob lives at the end of the record, validate it fits */ + if (jr->load.p.total_size < sizeof(jr->load) || + jr->load.code_size > jr->load.p.total_size - sizeof(jr->load) || + jr->load.code_size > INT_MAX) { + pr_warning("jitdump: invalid code_size %" PRIu64 " (total_size=3D%u) in = code_load record\n", + (uint64_t)jr->load.code_size, jr->load.p.total_size); + return -1; + } + sym =3D (void *)((unsigned long)jr + sizeof(jr->load)); code =3D (unsigned long)jr + jr->load.p.total_size - csize; count =3D jr->load.code_index; --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A2FD471D09; Wed, 5 Aug 2026 13:31:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936691; cv=none; b=ERsdnf3ahxUgW4e3BoQm+wAtW+q03qE4CQUuvcLko72pxi2U1coXVEARc3Dwdugu6abUTd3hHNVVfOxdV1DwnIUuQlFhX0isxw/LyuFKT7FcLlM82luxy2yYSkJasgLE6Yqmo0oRxEzxeGbVubUl5BIjTZxXiTK3rIIJn/vQv5U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936691; c=relaxed/simple; bh=+eET+vtLrV+dDxyeP+Jq1Slogc/Rmdn3ZTNkCK/wlvY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dik66SPhRSMoNivsBX8bA/zWjoM+ZkoUdkPqqKBUMOJhDmLLp6WKusaEa/1gv2q0i+ntlLrdOBeAao91c2xe24VYyLWVmAaLwRJh7MjkuaSc2o52Cxx2yfETegzwL9wveOUgOiDdmZAuJLLRS3E9pacslSEKJBC+WMajQmhJJiQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=PsJkf94/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="PsJkf94/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D82771F00A3A; Wed, 5 Aug 2026 13:31:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936689; bh=myGsoeIiu4huum95gabL7WYLI7F7P1PM7rMMi2FE1aw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=PsJkf94/OZy0wIZBb1SQnkXM9hdpoDusjeitFAi3pQeaMj49plHWQTG5hslrLuVaE O9YEt6mX6pBTkSKKTGnM3PnRrduNuOHMsTmHKCKh1jL9I9opVGEJP7LKzJoeii8VRD qxxQSnVxKU8Te5jcj24vcNYJa19qEc7ujSjQAaJaJYLndhIi8YqCfrHKRoj9gYIWhT MmhfIY7s6SLMNUsLLxXV+gJh2Ce7788JB4Gzt0jDqK2YQs32d1wOxqX7eoGaKMyciq kGtJ4TT/QCwlbvvokHvZ3yVp+Gx8Fb8YF1qM9aj0Wxx4ddC0WHM2W8coH+fYZSbqwh Szcvn9NpqAvbQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian , Stefano Sanfilippo Subject: [PATCH 03/12] perf jitdump: Prevent integer underflow in debug info size calculation Date: Wed, 5 Aug 2026 10:30:02 -0300 Message-ID: <20260805133013.235016-4-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo jit_repipe_debug_info() and jit_repipe_unwinding_info() compute payload sizes by subtracting the fixed header size from total_size: sz =3D jr->prefix.total_size - sizeof(jr->info); When total_size is smaller than the header struct (from a truncated or corrupted jitdump record), the subtraction underflows to a massive value, causing an oversized allocation followed by an OOB memcpy. Validate that total_size covers at least the fixed header before the subtraction in both functions. Fixes: 598b7c6919c7 ("perf jit: add source line info support") Fixes: 0284fecd13b6 ("perf jit: Add unwinding support") Reported-by: sashiko-bot Cc: Stephane Eranian Cc: Stefano Sanfilippo Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 3195f94187164066..787f8a03dae87908 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -669,6 +669,10 @@ static int jit_repipe_debug_info(struct jit_buf_desc *= jd, union jr_entry *jr) if (!(jd && jr)) return -1; =20 + /* total_size must cover at least the fixed header */ + if (jr->prefix.total_size < sizeof(jr->info)) + return -1; + sz =3D jr->prefix.total_size - sizeof(jr->info); data =3D malloc(sz); if (!data) @@ -696,6 +700,10 @@ jit_repipe_unwinding_info(struct jit_buf_desc *jd, uni= on jr_entry *jr) if (!(jd && jr)) return -1; =20 + /* total_size must cover at least the fixed header */ + if (jr->prefix.total_size < sizeof(jr->unwinding)) + return -1; + unwinding_data_size =3D jr->prefix.total_size - sizeof(jr->unwinding); unwinding_data =3D malloc(unwinding_data_size); if (!unwinding_data) --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2BE5146F4BE; Wed, 5 Aug 2026 13:31:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936696; cv=none; b=Stf7AOtlcwrgSFPs+Vir5sj95IqRpDAxUO5xc0tgNVj/WnIA9fEZz5WKQIK4mZEb/A8cwJ76OTP/PfxJoEG/upssir6CygiDjwLZXJWaGHtE4ZqYMz8lL7W78vfNoAErvZQcVIJvYQUOJZSDgsu2p3QQtsbBgI0eHuxYL0sHBrc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936696; c=relaxed/simple; bh=LLtfsq5IdqVNqzBiw7K0Qlaj1ChTEE+Zcuowt8R4cPI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=qarQJyGP+eo07m+lk14pSgqcym0TyqlCxtO6Plo1VTh66Z9WgdxhKU+yjPpKQRb1Iz+kcKFXifGCqRFd4P791lRp5fmPGrDSvD+8tAswPIfFTBN7/sE8ILgkL/MvkrmsiTCCOlSHilo5yS1njtUtHXAIkLlsVPbSxpkVc+jejxw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=gGbtsiB9; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="gGbtsiB9" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9249C1F00A3D; Wed, 5 Aug 2026 13:31:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936694; bh=ZVKRz2nkvbsV2c2B+Exqm/qaG3jK1ceYpyVXldsTxSA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gGbtsiB9+DQY6dxIeyM8ba3ULGnCmT8wIxxISZcuHxpXP2nZDz8eukWoBTRt1ml4Z ExrR0Dt11veSv/lDN5j+51eFiWK34noydPacss2dX4DbmWiX7cP/wxUtxcgnZJzs7G k0544SF/K+okYiAAVwOR4wkAC5bV4rXOfzWWOH0e+5Rxg2SknLhS8VdgcFXdRBP/Vb BjqJ3aXhr/v/BXJ5028d+vJZPU/OXZOxZ3Zy+1A1QrhiPc4DSOBgdFkXhWXRbDlfPV e8N4PDuwqKHWG9RqdKlVMpNpSwEX8JVlYRrcjhvLngFGp5s1sPhKwOCMfYhaegUsEq K2eGJEueiBNOg== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 04/12] perf jitdump: Bounds-check debug entry byte-swap loop Date: Wed, 5 Aug 2026 10:30:03 -0300 Message-ID: <20260805133013.235016-5-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo The byte-swap loop for JIT_CODE_DEBUG_INFO uses array indexing (jr->info.entries[n]) to iterate debug entries. struct debug_entry has a flexible array member name[], so each entry has a different size. Array indexing computes offsets assuming fixed-size elements, landing inside variable-length name strings after the first entry and byte-swapping garbage. Additionally, nr_entry is read from untrusted jitdump input without validation against total_size, so a crafted value causes OOB reads. Replace the array indexing with debug_entry_next() pointer arithmetic (which correctly accounts for the variable-length name) and bounds-check each entry against the record's total_size before byte-swapping. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 26 ++++++++++++++++++++++---- 1 file changed, 22 insertions(+), 4 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 787f8a03dae87908..078d3304d2b7ebce 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -318,14 +318,32 @@ jit_get_next_entry(struct jit_buf_desc *jd) switch(id) { case JIT_CODE_DEBUG_INFO: if (jd->needs_bswap) { + void *end =3D (void *)jr + jr->prefix.total_size; + struct debug_entry *ent; uint64_t n; + jr->info.code_addr =3D bswap_64(jr->info.code_addr); jr->info.nr_entry =3D bswap_64(jr->info.nr_entry); - for (n =3D 0 ; n < jr->info.nr_entry; n++) { - jr->info.entries[n].addr =3D bswap_64(jr->info.entries[n].addr); - jr->info.entries[n].lineno =3D bswap_32(jr->info.entries[n].lineno); - jr->info.entries[n].discrim =3D bswap_32(jr->info.entries[n].discrim); + + /* + * debug_entry has a variable-length name[], so array + * indexing would compute wrong offsets =E2=80=94 use + * debug_entry_next() and bounds-check each entry. + */ + ent =3D &jr->info.entries[0]; + for (n =3D 0; n < jr->info.nr_entry; n++) { + if ((void *)ent + sizeof(*ent) > end) + break; + /* name must be NUL-terminated within the record */ + if (!memchr(ent->name, '\0', (char *)end - ent->name)) + break; + ent->addr =3D bswap_64(ent->addr); + ent->lineno =3D bswap_32(ent->lineno); + ent->discrim =3D bswap_32(ent->discrim); + ent =3D debug_entry_next(ent); } + /* clamp so downstream consumers don't overrun */ + jr->info.nr_entry =3D n; } break; case JIT_CODE_UNWINDING_INFO: --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5D3D046F4BE; Wed, 5 Aug 2026 13:31:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936701; cv=none; b=udgUxJe/7N39vAt1O7iABxN7gX0/bnKNs1ZpVqjAGEg0XuxicQ3dkoZkfBsP0H8VBquYOxciBHLd0L7vO35vAw9IWmuBfU2iF/WY7WEiL/3mwkqjIMwN/GK+9m/UK0N6kR/pK0UfMYdlOXgqc8pObdkduffVBh+aC2jUZ+X6J9U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936701; c=relaxed/simple; bh=ikFrrWyhMBfQZqRUpaRPSY0QmwmGXvUmdIyzmUukMGk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mBw+/cqkAf2C+//CXD2lrUKEPvNe44g90WKm0+NlWIsxGey+7i7rtph3fWIqtJnL9eJSn0DPf6q7hYc47yc4XkElQPT8I1JcKLAEc7ciTRX6+a/A4FXDLJEgX5kIuFrXjH56F6Jdb/UdpIhbTuPTc1ZAAjX7/4Qutk1jxYz2Tqg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=UXkMWRBW; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="UXkMWRBW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6515A1F000E9; Wed, 5 Aug 2026 13:31:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936700; bh=SVk7zPpKJa5wyALqfhsZ+WOrOVCyDvZ0JgLmgyEfUfM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UXkMWRBW9E9QlAidu9FmIrYhq3S3qvgkw6qOs9MHAPmlDzLYvlx8JR/Xd4qmKjpt1 bzdZkRxVn4UtnXRVsw/Bm7jtMv9isIeEkKvY99otYAft4LM93F5gyZ1dIMH/SpNpPy tqehzcsBG+x+jGpTwtFUl6nA7k5jE6jMdT0aitXvfgVrN7ULa90ViWMV32SVi3bZsA KaUTNSCS36fCm9K/vT3qdNIAihgbAolJ6T178X0wHYBwaMPVTpmEbXObJPj2WlkHsW BoHTcLlq2BC+MR+X7FNlU+svtzbgGBHxxUuS4j3cv60mrj0jDxMwzyRWBnOW0cJxS2 hJIs1pcxooQHw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 05/12] perf jitdump: Check snprintf return before computing header size Date: Wed, 5 Aug 2026 10:30:04 -0300 Message-ID: <20260805133013.235016-6-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo snprintf() returns the would-have-been length on truncation. When the jitted filename exceeds PATH_MAX, the unclamped 'size' value inflates sizeof(event->mmap2.filename) - size into a massive underflow, causing the header.size computation to write an oversized header. The subsequent write to 'id =3D event + header.size - idr_size' then corrupts the heap. Clamp size to PATH_MAX - 1 after snprintf in both jit_repipe_code_load() and jit_repipe_code_move(). Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 078d3304d2b7ebce..fd11e07bf00b7978 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -493,6 +493,9 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd= , union jr_entry *jr) jd->dir, nspid, count); + /* snprintf returns would-be length on truncation, clamp to buffer */ + if (size >=3D PATH_MAX) + size =3D PATH_MAX - 1; =20 size++; /* for \0 */ =20 @@ -623,6 +626,9 @@ static int jit_repipe_code_move(struct jit_buf_desc *jd= , union jr_entry *jr) jd->dir, nspid, jr->move.code_index); + /* snprintf returns would-be length on truncation, clamp to buffer */ + if (size >=3D PATH_MAX) + size =3D PATH_MAX - 1; =20 size++; /* for \0 */ =20 --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D0B62F7EFF; Wed, 5 Aug 2026 13:31:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936706; cv=none; b=ulCpJ+4nxr9lZ0gYt1uX+rZ7lhOnT8u71RFPgqcAzbkWMxvyDz3I3O38Ac4SY+TE+UGSdHVz/jy6IAcsU9N6ORaeXTnYfJ/KBSK7nuIEBAqJlYkNe5r1516K5g+F7kAtpYM3zBuDCZd8OeZQV2z7NGIbyVBhHNrDAP9B/ibkA78= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936706; c=relaxed/simple; bh=geZvGpWtCpSHvuOy88Iz4tlsILhjVeHi8M1bwDQRjbU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=RWA4o5RTBVbGlwSSqfE4Eno0cxg4YpYwq/vl+1ipaWAeR+54hqfnuWB9y0QtQkI7LaC010XhEhSO8o+GkqsRY34xn0+ajE/pndejAX7kuulOVdHCvFIDrtTK/LurgDyv6P23mUVhxJEcYQUSDePXkNAFVXHIhtZw/k+s+zaO10A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ODoAKbcw; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ODoAKbcw" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9B7BB1F00A3A; Wed, 5 Aug 2026 13:31:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936705; bh=AMEg+V1cxs5MY7/YSPVJVJP2Y1cO8+LuG733zJV/BTQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ODoAKbcwOingCsjlbCt/TCNthqLQOpEa5wU/c/nHGvXwclBsKwB1DsQnz2kBCoZOq 5h2EWWwRWQJRBsvd6kuEupbexpHAjfiTt+Gpfp4ZwslurQ/DsYQLKtWwQw3Jv6540Z nJhfj0+9qbsVDPr1RUvrA3qHoKooEepYTm240uJ1AfqleSV11cWBcecvZ41vwDn0XH pney/ke4nMeOIgFxGHPrY+Wir6KpbxZi8yNPAXVyWNuLplDMGPV4n4sQxOCPZs1iqh s1CoUZtnKZnRoG3ZZSJSXNTVuhBJK87EnJ2MF8k/AoL8Uon3bVmE876CXUbzxF/MnC 7Mh92RrrQYocg== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 06/12] perf jitdump: Fix funlockfile on unlocked stream in jit_open() error path Date: Wed, 5 Aug 2026 10:30:05 -0300 Message-ID: <20260805133013.235016-7-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo If the malloc() for the initial read buffer fails, jit_open() jumps to the error label which calls funlockfile(jd->in). However, flockfile() is called later in the function, so at this point the stream was never locked. Calling funlockfile() on an unlocked stream is undefined behavior per POSIX. Split the error path into two labels: 'error' (after flockfile) calls funlockfile before cleanup, 'error_noflock' (before flockfile) skips the unlock. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index fd11e07bf00b7978..c3f11d1c1d76d6c7 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -155,7 +155,7 @@ jit_open(struct jit_buf_desc *jd, const char *name) =20 buf =3D malloc(bsz); if (!buf) - goto error; + goto error_noflock; =20 /* * protect from writer modifying the file while we are reading it @@ -244,8 +244,9 @@ jit_open(struct jit_buf_desc *jd, const char *name) =20 return 0; error: - free(buf); funlockfile(jd->in); +error_noflock: + free(buf); fclose(jd->in); return retval; } --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AD68746F485; Wed, 5 Aug 2026 13:31:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936711; cv=none; b=S/8BDFKwajKFXPUXSVdBiJr8kl3rX/ClKPze+AbI2y4sRXSrtrV3uVatMA8B3H1M50ZjX8DTdb21fgqb/eZDxKpxLfcf7+0m578TL/RPeWD6Kcy1XucfLYDplHsKg/QzVS77X5NPz0G9ajGsQNFLRGkobbWPyNwVuPHJTZaf22k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936711; c=relaxed/simple; bh=pW3uCAG3vsiuBF2sw9z/uSPSTEDAboYxHg1CaOEJbbQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=OIRwPTH2eioQ882nmVq7cB+sobSLqVp/Eho/Tik1F2+8q4lGQN/ilRrbdSOLOl2vMV2oOxSAT+kISQhLjB2Rojf1+6DRPLKgh5j5IBq3bcTBcUNyoorO0ZFQsgvA/8nnz+do1VG6vZIPmjmiAcMoNnGbVNBfmioaQGpn/oVMhV8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=U5wgdlTG; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="U5wgdlTG" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8C3271F00A3D; Wed, 5 Aug 2026 13:31:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936710; bh=IebGWcr1gbp+6aNhwdRln7VWAiSH8dm1KYaLctFflwM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=U5wgdlTG7nmzSVfXkG4sa0aY5m8UlLK068YMK1oJ/+trZIyyfQCkDiG3Z/Gj4EwDj UbGGWEQBn+N0iKWf+nv8BpAY2WLsaFbblASwPagVMcjS62lvLyZt4FvHxpvrm1jeGo hXEFzmkIhLwdDfELCNrUSzE83EcyLINyYO3gGMr17pOzEWvGcA9TEQtygqSAr38iic XjnVrXSAu/lQm8RN0BkyTOOfvMwVNeShkM9Grw+zZxcJdr4zcGx29D4arWJu+IFXTh /pAtcOYETECQrj2h524dafJPoMT+se6IQQu7JEDX5mwI06dkCYxti28ioc7wGO6lbT ilcWBar0Ev0/g== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 07/12] perf jitdump: Free event in jit_repipe_code_move() Date: Wed, 5 Aug 2026 10:30:06 -0300 Message-ID: <20260805133013.235016-8-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_repipe_code_move() allocates a perf_event with calloc but never frees it =E2=80=94 the 'out' label exits with only perf_sample__exit(). The sibling function jit_repipe_code_load() correctly calls free(event) at its out label. Add the same free(event) to jit_repipe_code_move(). Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 1 + 1 file changed, 1 insertion(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index c3f11d1c1d76d6c7..4f52b143cd0da296 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -683,6 +683,7 @@ static int jit_repipe_code_move(struct jit_buf_desc *jd= , union jr_entry *jr) build_id__mark_dso_hit(tool, event, &sample, jd->machine); out: perf_sample__exit(&sample); + free(event); return ret; } =20 --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A9D7471D1B; Wed, 5 Aug 2026 13:31:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936717; cv=none; b=mpzNxuAUYxFDwIWLXvGY8JRekBmIn57JGZEO3bSTC2BkgdLin4CkIFd7SLo1yqMHnKGTC7MTtMHXC7g+CB83qX5pKmFgSa1HJA5NeVwB9Ba1lSS5U9j0OULJ9xrokNxQYkjusmM1eYpsxKjq+DpcaMzmxbkF6F3epYUQ6afg3bg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936717; c=relaxed/simple; bh=bta2pOcbWdz9aAjl0CLXJRXhtW4lkAh8toFj4jLc0wQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=YXSXkplYRvMd6KBaUxqukRqPgf4KY9v1bjO8tHgY32oIkUPL50awyZSj2AV8AIxlHiEGXtZDHBY1g+wBmRVTS7QeqX7KqtMmkf6lXynVUINh0PGh4DITYGc6RvmtFy4Sii85CgA3znX/Ro/H275ycd0bWfiHTXdnsyJy5KYT36A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=l4eXu8Nw; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="l4eXu8Nw" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EE9D91F000E9; Wed, 5 Aug 2026 13:31:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936715; bh=gVACmEeIsofelsaO+fkSZT0+60oC4q8ndjcwBqEGF8Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=l4eXu8NwX5e0wxNOQ2A0uw3QZ8sSu3sxnk0DcIwaRWrIwv3pu32oy06XMRKoN119l 3TeUgI2iXXS2PE0G7C9aemLMrAGNeOyWXeEhUhZsQ5BtEA4a0DdGBdng11qp2B8plj 9dcP4HwkPoZgB96yZJfN6JXLQQB8qx3XQK+72lDTGY1oYp1WZes/ZbeOStzBsaukbo lMTy5hxV5BZr+Pg7fm7y9rOjfhE+8r1Uyl2PIEcdtptSt5TAEB3vrRnuQ//V4LlzOa Ecy8MkPUdchkel50OnzPSCXrP85ddSBBWTrWoZqMndpuDaPYvzCK6GpEaRi4EPYzUg WWEatasF9aFiw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 08/12] perf jitdump: Fix debug_data and unwinding_data leaks Date: Wed, 5 Aug 2026 10:30:07 -0300 Message-ID: <20260805133013.235016-9-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_repipe_debug_info() overwrites jd->debug_data without freeing the previous allocation. If two consecutive JIT_CODE_DEBUG_INFO records appear without an intervening LOAD record consuming the data, the first allocation leaks. The sibling jit_repipe_unwinding_info() already frees the old jd->unwinding_data before reassignment =E2=80=94 add the same pattern to jit_repipe_debug_info() using zfree(). Also add cleanup of both buffers in jit_close() so they are freed when the jitdump session ends, even if no LOAD record consumed them. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 4f52b143cd0da296..3085091b95a517ae 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -118,6 +118,8 @@ jit_close(struct jit_buf_desc *jd) funlockfile(jd->in); fclose(jd->in); jd->in =3D NULL; + zfree(&jd->debug_data); + zfree(&jd->unwinding_data); } =20 static int @@ -706,6 +708,7 @@ static int jit_repipe_debug_info(struct jit_buf_desc *j= d, union jr_entry *jr) =20 memcpy(data, &jr->info.entries, sz); =20 + zfree(&jd->debug_data); jd->debug_data =3D data; =20 /* --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9B5FB471D1B; Wed, 5 Aug 2026 13:32:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936722; cv=none; b=HHEhT+IYY/JNGhWKMI4Uv8ldT4tUv6+OvWKNkM+o9Oqt5mUjWAG5SA9iTcupFXpm9NRwT5MX8JDz4EM0JWFifEvERy6nnDCdFPFCR8BhIhwfPFyAXbswMHleQCLBAUVFmLZiKiNa6T5Lv1VaJJ14JP8EoaUw4+T23WMa8dLmAqk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936722; c=relaxed/simple; bh=xF81jda+5dqYafQlyt1xrp7a0Ji5p/BUDTIbscvLN8A=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Ezl9e9hpPyctsOa7EbJge2yN4u7y0uzQXAIk3qQHRc9dtYv6E9O3jN4PmbPeZ73LHv3OtAt0px/ip4rvB5zBAO8tmbHFQ7eennZXCQOMs6brKb4bis/jSDCanhZav3419VMib0hPlf2I0z1VALdUtJ+IUzFEQkX9ekWNzBWxfaM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Fkzto8yk; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Fkzto8yk" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 7C46F1F00A3A; Wed, 5 Aug 2026 13:31:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936721; bh=iuGw7UmKVJcSVp1OPKsiB3Zy+LN8qE51vkEEpa+vI+c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Fkzto8ykWHQBFrLG4VuMczmt9hoBPJ6GEGCLPjspmzltwN49Urcn/0RMQgnteNd4M Ejycuqmzo1JFw+lCSz9jzCeW7hoCcp0UdZkD4b7aGx4/hXo/MJOvljyYTk2oB9wnkR abbHsm6pjX0KOCgFv90lbsDmQTWk+sZUH5bXRBu4fGcEVgPBR5kid+To98qTWR5OUl rHZPoWaoI4XQcU4xb9LmoECR46rSLRvdQtC3p9zp4iMzUy64ZT8bclJy+d+I0Rs3zC xLuKZf+Bf/J0GBL9mJ2GeIrT7U2IEzA8oyDLLzfOGDJ8MRMRsVhzlyJ3Sb4NVX26m+ DKtpSwvdo85sQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 09/12] perf jitdump: Use dirname() return value in jit_open() Date: Wed, 5 Aug 2026 10:30:08 -0300 Message-ID: <20260805133013.235016-10-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_open() calls dirname(jd->dir) but ignores the return value. POSIX says dirname() may return a pointer to internal static storage =E2=80=94 gl= ibc does this when the path has no '/', returning "." from a static buffer and leaving jd->dir unchanged with the original filename. Capture the return value and copy it back to jd->dir when dirname() returns a different pointer. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 3085091b95a517ae..02840dbf8a1fc16c 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -146,6 +146,7 @@ jit_open(struct jit_buf_desc *jd, const char *name) ssize_t bs, bsz =3D 0; void *n, *buf =3D NULL; int ret, retval =3D -1; + char *dname; =20 nsinfo__mountns_enter(jd->nsi, &nsc); jd->in =3D fopen(name, "r"); @@ -241,7 +242,9 @@ jit_open(struct jit_buf_desc *jd, const char *name) */ strncpy(jd->dir, name, PATH_MAX - 1); jd->dir[PATH_MAX - 1] =3D '\0'; - dirname(jd->dir); + dname =3D dirname(jd->dir); + if (dname !=3D jd->dir) + strlcpy(jd->dir, dname, PATH_MAX); free(buf); =20 return 0; --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A831047277C; Wed, 5 Aug 2026 13:32:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936727; cv=none; b=r6VIRDlduGSR8cILR8a/TqtQ0qZW4EnPRZEWlPZCRyEGnw9blnhwgMPtlZSd5WUdBAAhCGMe1LOaPI+f+3N128XWsQX3V/nmTl7MaJsEMiVarH4NOYuhOd4cc4az5HNWH7oiKHkLgiZ+mNaWN81AQOmDmBeFq+QUZuioskE4aKY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936727; c=relaxed/simple; bh=OppWOfMkaD8AmvoQxLEpbmpYg/DgP84tAUTmp045jQU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=RQNM8YGPynzymsfIhGoZD3Aai28f2ZMIJInothnRVfEd1nibj33xJTtrVRFLmQaFQWpz5JhnP/WEz4OXQFr2U9npZf92FR6BZsU8FL4egcpg6zGOtxgFScuYOTvfiZ9w/yFkcZia79muPavCcRRxiQ6eJ7WDIklcVzOw8vBty10= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=auFTQJvz; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="auFTQJvz" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E48B51F000E9; Wed, 5 Aug 2026 13:32:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936726; bh=E613IRkQNGwdjNPYGRqbp3+jcaqY5Ab60reOU0zoRdc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=auFTQJvz0/P285MIM3JW+xvcfliQBQfWHnpHQtra6ayn9Bn3VAQ12CrNIyf9LNL3u CMbfnUsNBqxsRgDyQZ3jlD2McRM2xl2O5/vpVibxRtU51Z8HmAE7wKbX3lCFF7e4cy O75kiTClyy14jlWBCUvmg2Yq6CuvlX/Zo32lm9pdImaRDPq01odGFdgBl4Kou2QBSQ Rn2TlJsuxJFTCDWZPFvGwhHlHQdHQ0C0rGprqVLdruoAzqUpGrhizb5GOy0R+Tw+9c yNo+nPxy5irsx6egU0iLuUrjIKnjsqVitOY6fHEOx3mevScDVcp9Wv4aZbNSiqXD7G pKXW3njbzBj6A== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 10/12] perf jitdump: Validate debug entries on native (non-swap) path Date: Wed, 5 Aug 2026 10:30:09 -0300 Message-ID: <20260805133013.235016-11-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo The bounds-checking and nr_entry clamping added for the byte-swap path only runs when jd->needs_bswap is true. On native-endian files, nr_entry passes through unvalidated to jit_repipe_debug_info(), which stores it as jd->nr_debug_entries. Downstream, jit_process_debug_info() in genelf_debug.c iterates nr_debug_entries times via debug_entry_next(), which calls strlen() on each entry's name field =E2=80=94 a crafted nr_entry causes OOB reads and writes. Add bounds-checked iteration in jit_repipe_debug_info() that validates each debug_entry fits in the payload and its name is NUL-terminated before calling debug_entry_next(). Clamp nr_debug_entries to the count of valid entries. Fixes: 598b7c6919c7bbcc ("perf jit: add source line info support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 27 ++++++++++++++++++++++----- 1 file changed, 22 insertions(+), 5 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 02840dbf8a1fc16c..87612ef3e232598e 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -694,8 +694,10 @@ static int jit_repipe_code_move(struct jit_buf_desc *j= d, union jr_entry *jr) =20 static int jit_repipe_debug_info(struct jit_buf_desc *jd, union jr_entry *= jr) { - void *data; - size_t sz; + struct debug_entry *ent; + void *data, *end; + size_t sz, valid; + uint64_t i; =20 if (!(jd && jr)) return -1; @@ -715,10 +717,25 @@ static int jit_repipe_debug_info(struct jit_buf_desc = *jd, union jr_entry *jr) jd->debug_data =3D data; =20 /* - * we must use nr_entry instead of size here because - * we cannot distinguish actual entry from padding otherwise + * Clamp nr_debug_entries to entries that actually fit in the + * payload. The byte-swap path already does this for cross-endian + * files; validate on the native path too, since downstream + * jit_process_debug_info() iterates via debug_entry_next() which + * calls strlen() on each entry's name field. */ - jd->nr_debug_entries =3D jr->info.nr_entry; + end =3D data + sz; + ent =3D data; + valid =3D 0; + for (i =3D 0; i < jr->info.nr_entry; i++) { + if ((void *)ent + sizeof(*ent) > end) + break; + /* name must be NUL-terminated within the payload */ + if (!memchr(ent->name, '\0', (char *)end - ent->name)) + break; + ent =3D debug_entry_next(ent); + valid++; + } + jd->nr_debug_entries =3D valid; =20 return 0; } --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 20269472795; Wed, 5 Aug 2026 13:32:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936733; cv=none; b=rJ1NpziNgQbXN1V5pBHagtBCBdghRDpZcP2EbUjlctknbm3tmLu0czIGVexj/nA6y3t9SnG7XXkyqwGP3TraSeLHMLtgtFt339d8NSMfDjZXA2ilZuIkolhh/VGneF3MB8r2onqcL2mrtWw2k6Vu9k3Vhk6ZcHQcbCYParTlJLc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936733; c=relaxed/simple; bh=HTnHt8qDEbGHfbkkfRXglCVlsHIhPAOEO/9676Dk6D8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JpzHLxulYF9T1rrqPxYoTR5KBww3Bup9D4SPMzD417/HuaJdOY2h6v+ISfy1i0vhH/WFz3G/k46I7jJ/srsE+iAtpFPIyF59OYnTPQqr3D6FI9hoqjDQxn4fqiMPMgLMGXuYQg0MIsjaoksLFEnZcRmBdfEGOODajjFYtdkr00A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Uk/dt4LO; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Uk/dt4LO" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E87911F00A3A; Wed, 5 Aug 2026 13:32:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936731; bh=sYtXTN3C/+goSEj0OlgX2fHRZYMewH2qDu7nAKAo7Ps=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Uk/dt4LOkbvE5YpPVQXRwmDWYzc9BmgAvnY0Kx4Q/tMJk005KH6SLOPwEvAfZV15Z zrfYWG+F415FCfyt2h+/ZPNsHUB4vf7jlueLn+lrjRwlOSxT1GSo3Np35Lt3FmslWG OgtmkVjyIKPsEUuc3AXcY3QMKDE8u2VZECfkuoe3/cq+hwflDTX+J59DRp6wulpkGZ sfVWi599hjvble48Jr2bpaE7KKAZyflG7jjVEKYgeaQg5NHvhD+Tv6ebztvBSRdVCo B5Wd+350kyn4p9JDbqrGD+Zk2r1VU3vz8dxVE+MYHaLOwzGCX9S7WJVQM9fg6C8BP7 hEbJqka6kX0kQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 11/12] perf jitdump: Validate sym string NUL-termination in code load Date: Wed, 5 Aug 2026 10:30:10 -0300 Message-ID: <20260805133013.235016-12-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo jit_repipe_code_load() computes sym =3D (void *)jr + sizeof(jr->load) and passes it to jit_emit_elf() which calls strlen(sym) via jit_write_elf(). If code_size equals total_size - sizeof(jr->load), the sym pointer aliases the code blob with no NUL terminator, and strlen() scans past the buffer into adjacent heap memory. Add a memchr() check to verify the symbol name is NUL-terminated within the region between the load header and the code blob before use. Fixes: 598b7c6919c7bbcc ("perf jit: add source line info support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 87612ef3e232598e..5f3a53f818c29f58 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -487,6 +487,13 @@ static int jit_repipe_code_load(struct jit_buf_desc *j= d, union jr_entry *jr) =20 sym =3D (void *)((unsigned long)jr + sizeof(jr->load)); code =3D (unsigned long)jr + jr->load.p.total_size - csize; + + /* sym string lives between the load header and the code blob */ + if (!memchr(sym, '\0', code - (unsigned long)sym)) { + pr_warning("jitdump: unterminated symbol name in code_load record\n"); + return -1; + } + count =3D jr->load.code_index; idr_size =3D jd->machine->id_hdr_size; =20 --=20 2.55.0 From nobody Sat Oct 3 04:00:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00EDD471CF0; Wed, 5 Aug 2026 13:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936739; cv=none; b=tq9uYGIbNFBZr0nApvS6OCJUa23XGMtP+jUdNgxwcfAKFEAJNErh3Cafp0xyEroFgUOt8qUxaC4C+HqXfD79nq16ogkaSdiQv1YMrefsYfudUeAxS/5zScMR4pzW4ORPki+060ZKlroTjzo7LY9iBl7FFsVE0Uem9LlgBA/cAr0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785936739; c=relaxed/simple; bh=Z9ve3VePHvgxNnQWepD9bC1ZY55vMh+oLJknABsCgig=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=EBKJlCVDFms1F0CKS5Rl96Yjg7ezUYZ0i4jqMmzbrcWPMhsPgwqFfuuRBwDbbNbniuTqm5zs9cFlptQC6ze/ifsanPwZwnT2JKrIN/0k2MUll9yGRDL9pYyuVVh7uzTlaDBnlw3tVsgwYfcsapWb9X+xTd2+Q6gZbzzy7K8SqSo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VDmXji5B; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VDmXji5B" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 766B41F00A3D; Wed, 5 Aug 2026 13:32:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785936737; bh=Tt9e1Mvz3vTp4zLB+5t4Nnez5r9pqUFhpFkk+ukJ0XM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VDmXji5B5p53PB98eUWrsgjhn5e4+BcCn9rfKwbTBKB6/H4zCG9czhpIRSTO/xbkX psEEL+DaeQyjLiffOZRxCvyF6BzvSyuIcLOpPx5d4ccgNPXk1/r+K/p2jV2vj5PQ4j vTzqIxUH9G2NeniULN6CAzuyodomSKst2xNeIm3bMpSLeSV4hzt4pHcykWxZj5OpRO +ORwONosHqIPI7CxRlkHj7cgIDstS+LnrsQsKmxv+XTG/86OYoipRctkBEHPOrSBxk u30ILCRq2AJXMFvVPG8hWX1xb9Eih3sQLH6KrPj5QQiPTlSLdyqm8DGnEvK9bFIl1f oMKA+NeLzTxKQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stefano Sanfilippo , Stephane Eranian Subject: [PATCH 12/12] perf jitdump: Validate unwinding sizes against record payload Date: Wed, 5 Aug 2026 10:30:11 -0300 Message-ID: <20260805133013.235016-13-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805133013.235016-1-acme@kernel.org> References: <20260805133013.235016-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_repipe_unwinding_info() copies unwinding_size and eh_frame_hdr_size from the jitdump record into jd-> fields without checking them against the actual payload size. Downstream, jit_add_eh_frame_info() in genelf.c computes unwinding_table_size =3D unwinding_size - eh_frame_hdr_size, which underflows when eh_frame_hdr_size > unwinding_size. The result is passed as d->d_size to libelf, causing an OOB heap read into the output ELF file. Validate that unwinding_size fits within the record payload and that eh_frame_hdr_size does not exceed unwinding_size before allocating or storing the values, so a bogus record cannot force a large allocation that is then discarded. mapped_size is likewise taken from the record and was narrowed into an int for the mmap2 len computation in jit_repipe_code_load() and jit_repipe_code_move(); values above INT_MAX would turn negative, producing a wrong mmap2 length. Use uint64_t for usize so the value cannot truncate. Fixes: 0284fecd13b6db3e ("perf jit: Add unwinding support") Reported-by: sashiko-bot Cc: Stefano Sanfilippo Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Assisted-by: Opencode:mimo-v2.5-free Signed-off-by: Arnaldo Carvalho de Melo Reviewed-by: Ian Rogers --- tools/perf/util/jitdump.c | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 5f3a53f818c29f58..385c19b864aeee4c 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -462,7 +462,8 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd= , union jr_entry *jr) u16 idr_size; const char *sym; uint64_t count; - int ret, csize, usize; + int ret, csize; + uint64_t usize; pid_t nspid, pid, tid; struct { u32 pid, tid; @@ -543,7 +544,7 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd= , union jr_entry *jr) =20 event->mmap2.pgoff =3D GEN_ELF_TEXT_OFFSET; event->mmap2.start =3D addr; - event->mmap2.len =3D usize ? ALIGN_8(csize) + usize : csize; + event->mmap2.len =3D usize ? ALIGN_8((uint64_t)csize) + usize : (uint64= _t)csize; event->mmap2.pid =3D pid; event->mmap2.tid =3D tid; event->mmap2.ino =3D st.st_ino; @@ -612,7 +613,7 @@ static int jit_repipe_code_move(struct jit_buf_desc *jd= , union jr_entry *jr) char *filename; size_t size; struct stat st; - int usize; + uint64_t usize; u16 idr_size; int ret; pid_t nspid, pid, tid; @@ -761,6 +762,18 @@ jit_repipe_unwinding_info(struct jit_buf_desc *jd, uni= on jr_entry *jr) return -1; =20 unwinding_data_size =3D jr->prefix.total_size - sizeof(jr->unwinding); + + /* + * Validate sizes before allocating =E2=80=94 jit_add_eh_frame_info() + * computes unwinding_size - eh_frame_hdr_size and uses the + * result as a buffer length for libelf. + */ + if (jr->unwinding.unwinding_size > unwinding_data_size || + jr->unwinding.eh_frame_hdr_size > jr->unwinding.unwinding_size) { + pr_warning("jitdump: invalid unwinding sizes in unwinding_info record\n"= ); + return -1; + } + unwinding_data =3D malloc(unwinding_data_size); if (!unwinding_data) return -1; --=20 2.55.0