From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 608433F2109; Wed, 5 Aug 2026 21:27:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965240; cv=none; b=QvuIcTBIb03W0HgRjB0RW5uj86K1qs130VyGX+d43taOeU7Dnumd4PVgveaBXIJb7CqudsvIHGLnKiGPkUEWwUPnVidOTHnBdAmsLmCic6ZGD+tuz/056ScdKildf1IQ5kKm9y+hcfiEQrd0O+qCC6op8ypEoWOMFVk6JV0yAp8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965240; c=relaxed/simple; bh=p1S8g7m1+MhoK7RRb87ukE8btgQpT7Hp/ZdsQZAHicE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=GeCwDLT2PT995506jqQq5hphYcQyeP2tklxTD/LQCblKiJdsLkDYQHJba6Ouppo2kS1LQf6R6MbxJEw7uXVquIKYP6hALQ9R7Gk7OwbHhfVun8yyqwTJjLdsiYjzhA97cQ0HKN4V5x6FkNZk4fjJC6uYWyOgYOGlTJnvvwnj6fQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=C9J9mR9z; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="C9J9mR9z" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 32D9C1F00A3A; Wed, 5 Aug 2026 21:27:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965239; bh=L+XgG3zRC2xuZyKC3GoSym/L/+7SSWd9pP/277f7PNg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=C9J9mR9ziHAYCLDcrxZBKit7lNIwCbdlYSdAI8FCcVB+D/pJqhd++2NS0scsKc0Ql OHai3I93zpgy2tlIWpiAogcBMNcrbMMxIcInxbQnk1BKnUIi4dZ5c4/nYU6NLvBNm/ UxjEf6QRd3zv+hgYuK5CWCU8uPK90Dgb5xgqU2l/1c4s+pwa3liqpqyq9mtsI36lLM D4il3aqm5PqETqwDSyy3NzrstDiIPJi29SqcWE4ayiBjjccxFXnIoXts1BmgzMAOGN 7rsyhYr4TRqDblPqIuUKrywBrUMGUswoRl/pEOl7hUb9A8xrve1j1kNiiDoAAKQkRQ f25MUOJaprRsw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 01/12] perf jitdump: Fix extended header read that always fails Date: Wed, 5 Aug 2026 18:26:51 -0300 Message-ID: <20260805212704.267779-2-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_open() sets bsz =3D bs before the fread() that uses bs - bsz as the read size, making the expression always evaluate to zero. fread() with size 0 returns 0, which triggers the ret !=3D 1 error path =E2=80=94 so ext= ended jitdump headers (total_size > sizeof(header)) have been silently broken since the original implementation. Additionally, when 0 < bs <=3D bsz the if (bs > bsz) block is skipped entirely, leaving extended header bytes unread in the stream. Subsequent jit_get_next_entry() calls then parse those leftover bytes as a jr_prefix, corrupting the record stream. Fix by separating the buffer growth from the read: realloc only when bs > bsz, then unconditionally fread bs bytes when bs > 0. Fixes: 9b07e27f88b9cd78 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Cc: Ian Rogers Cc: Namhyung Kim Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 83005b30b9bf3fd7..4b7c7ba7cd95ddbb 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -224,10 +224,12 @@ jit_open(struct jit_buf_desc *jd, const char *name) n =3D realloc(buf, bs); if (!n) goto error; - bsz =3D bs; buf =3D n; - /* read extra we do not know about */ - ret =3D fread(buf, bs - bsz, 1, jd->in); + bsz =3D bs; + } + if (bs > 0) { + /* consume extended header bytes from the stream */ + ret =3D fread(buf, bs, 1, jd->in); if (ret !=3D 1) goto error; } --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 49D8B30DD00; Wed, 5 Aug 2026 21:27:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965245; cv=none; b=sroVtLnsM/J+qNAlvt+xw4X7jCmtOyGceEUMITPEN1NpJFCMBIEYvkjivl/0efgRVzqQjNbfRbnMg4gHRfY9a1Ba9cSIwLaYsiQ9L45KU7UtFd0xKRROqvhj8FVdVh8xP6Js1XdjFBcWg17/6NT8ZvN1Rp9c0wxDEjNufxEwcok= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965245; c=relaxed/simple; bh=zlX7O/BpFVHV3tq4Eld5qB4iOfJvb7cAHwH74GEp7Gg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WNqvml2Tq4VT4B5c2StkBLjmyTx8bdOh3n2ZiuMcsEk9JM4JkM+Spy5CHBjZJA/7GEfxYbF0GBgkEWpKQQbi16VCiCARrwwMpt4JWJq3PcsHvNmQrkwm2Uh66fxnS3eg00iR3zsuk391uHXTWEWEtZjEbCtLsbodzeQGQl98+TM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=OWVnGtce; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="OWVnGtce" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B3E971F000E9; Wed, 5 Aug 2026 21:27:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965244; bh=KxWvW5q5uMzulHBaxK4RcYKPpMh5zPGil6RnCmC/es4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=OWVnGtceXQ9xSuUrvPBbspJAIdZ0TFf2kke7RUOfAp+P2vo3JasmApaG2LCDf1Sr5 OyQ8dRMqy03/aDdVgU7ouLBIchP8jUJTzCSEiI2IljAtMoGWKtHMoAKeB30GJMm8qQ Z6+j+cnVbzY8yi3/kCsRx01XaEjHD2zpjDV9bH0u1g8IGIgzih96StWa4COn0VsHxH UNDQzbF5H5zv9zKy717AlHDo6bUwgL2Zmaw2d8DfvIzqhG8yblUndjC1Q7A73hZrxX M67QYyowwkKUQCF7Nu1d2+zCX2iepNXXbo6Q9rG1ocb+1m/vdca2BIugOf5opGOF+h TnHeBruR1D87w== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 02/12] perf jitdump: Validate code_size against total_size in code load Date: Wed, 5 Aug 2026 18:26:52 -0300 Message-ID: <20260805212704.267779-3-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo jit_repipe_code_load() reads code_size from the jitdump record and uses it to compute a pointer to the code blob: code =3D (unsigned long)jr + jr->load.p.total_size - csize; An oversized code_size underflows the pointer arithmetic, causing OOB reads into earlier heap memory. Validate that code_size fits within the record (total_size - sizeof(jr->load)) before the pointer computation. code_size is uint64_t but csize is int; values above INT_MAX wrap negative when narrowed into csize, which defeats the bounds check and sends the code pointer past the end of the record. Reject those too. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Assisted-by: Opencode:mimo-v2.5-free Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 4b7c7ba7cd95ddbb..3195f94187164066 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -9,6 +9,7 @@ #include #include #include +#include #include #include #include @@ -450,6 +451,16 @@ static int jit_repipe_code_load(struct jit_buf_desc *j= d, union jr_entry *jr) csize =3D jr->load.code_size; usize =3D jd->unwinding_mapped_size; addr =3D jr->load.code_addr; + + /* code blob lives at the end of the record, validate it fits */ + if (jr->load.p.total_size < sizeof(jr->load) || + jr->load.code_size > jr->load.p.total_size - sizeof(jr->load) || + jr->load.code_size > INT_MAX) { + pr_warning("jitdump: invalid code_size %" PRIu64 " (total_size=3D%u) in = code_load record\n", + (uint64_t)jr->load.code_size, jr->load.p.total_size); + return -1; + } + sym =3D (void *)((unsigned long)jr + sizeof(jr->load)); code =3D (unsigned long)jr + jr->load.p.total_size - csize; count =3D jr->load.code_index; --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4DDED3D3D19; Wed, 5 Aug 2026 21:27:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965251; cv=none; b=AN6pY1epO3VAtbCNckXdqvoqdS4C3XjIHshANWWBsXstvdD70JjKVIRwxlvwAUqv52t22G3mLnCR3eCPjd56D0q54FyLBAdpoa2OIBGe2UmpvoI1ct7d1lN/W4YOFrFEkYSBAXA07QxJNWYKqBcULHFgWDgrnBTkRphDh5cO3KU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965251; c=relaxed/simple; bh=Wb2xZcqLk/LfUZrlS4qIBOQJumipMmIBOOqN6qIC+Xs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PwIlvpuSYBXuEN4ZXQReNjKaaTnSmlKcf13gD3GE275sGOzVfiTgN6lovCUDzzoYMLn/Ggt0kJmluWi+zTIgcf0FUjBb6Q4WtOtJRiU7qPlS2CwwS3mf2aZjOaV5JLNkFwM6LDsvzl5hVO8Z8AsgeWbSnz8jhnfHrd/oSdZIFMk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=a/U9nyR4; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="a/U9nyR4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D12E91F00A3A; Wed, 5 Aug 2026 21:27:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965250; bh=2jxMekgF7EH2vsd6qPmdNi2taLUCZjohv1qadWzRXBQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=a/U9nyR41QWn/vaXTFzbo0zsck0PB690pm96KYt8h5xmpdJv9lcsbjkC8EigK2olV MPeddBuxqv9+5+R6YjLhKMwYd9RhH70aTKqAGL3g/YE45bmh0QILDLQIhhseloZvUr dGfybaZEKcVGxOQ5QyS8+9cUxMD44iPds3bkUflXSqPnoqVgKH5dAjyn+OQwswB2hz 1NjyhmXmRygUYL6vTRszaYtoVkLsCU9TcUNgeVuVlk6XYlz8VZJRyDnqgcgve2Ccuj A7ix+2o6grrdPsXMiyJBsBHlG8f6zG9w0DP8UW3egva7CqysL7w7CxBVCryetsA2TA XU8LuCHh8JTMw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian , Stefano Sanfilippo Subject: [PATCH 03/12] perf jitdump: Prevent integer underflow in debug info size calculation Date: Wed, 5 Aug 2026 18:26:53 -0300 Message-ID: <20260805212704.267779-4-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo jit_repipe_debug_info() and jit_repipe_unwinding_info() compute payload sizes by subtracting the fixed header size from total_size: sz =3D jr->prefix.total_size - sizeof(jr->info); When total_size is smaller than the header struct (from a truncated or corrupted jitdump record), the subtraction underflows to a massive value, causing an oversized allocation followed by an OOB memcpy. Validate that total_size covers at least the fixed header before the subtraction in both functions. Fixes: 598b7c6919c7 ("perf jit: add source line info support") Fixes: 0284fecd13b6 ("perf jit: Add unwinding support") Reported-by: sashiko-bot Cc: Stephane Eranian Cc: Stefano Sanfilippo Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 3195f94187164066..787f8a03dae87908 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -669,6 +669,10 @@ static int jit_repipe_debug_info(struct jit_buf_desc *= jd, union jr_entry *jr) if (!(jd && jr)) return -1; =20 + /* total_size must cover at least the fixed header */ + if (jr->prefix.total_size < sizeof(jr->info)) + return -1; + sz =3D jr->prefix.total_size - sizeof(jr->info); data =3D malloc(sz); if (!data) @@ -696,6 +700,10 @@ jit_repipe_unwinding_info(struct jit_buf_desc *jd, uni= on jr_entry *jr) if (!(jd && jr)) return -1; =20 + /* total_size must cover at least the fixed header */ + if (jr->prefix.total_size < sizeof(jr->unwinding)) + return -1; + unwinding_data_size =3D jr->prefix.total_size - sizeof(jr->unwinding); unwinding_data =3D malloc(unwinding_data_size); if (!unwinding_data) --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A341C3F4100; Wed, 5 Aug 2026 21:27:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965256; cv=none; b=ucgb2iXhbtCREaKHQsDoBza5j+fpQ552X+a/4WpY5mUkWrBPQOuQbaWXcltNaR/40A/LU69TJPKYuU+B0346Bys7lCSgMNP/zVdGT2ltMvVTKIyqhDN7Sfz9uHxZjMhlGj2a97kwaPsrWQiAczgqAlbqxJhe3q03ppmSst909xk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965256; c=relaxed/simple; bh=+/J9xlSydRSCdHiqZYWd2sDpcpkUtFlKTDmmX8DCnVE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=mesprcV48dPM3WMTYsM1Nk3mZ58b9BIYARjZDyjrRQ4Xn4F+uhFT998rb0KOnBBQX4oS6qcrGMr3CbtbFqwal1SkoExMcYX/JFQryg4Qft6Ji+NvqpH+z0XH12vfwaI681nuf0A9SHI5MLeiHJdWWcqW+F1eWY72dn63mrh8UNY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=b3RcKTVx; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="b3RcKTVx" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A9AAF1F000E9; Wed, 5 Aug 2026 21:27:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965255; bh=8VgoHQ+EUFWlf9ftGCRRwShE2uFPvLMrq5ebedr1m8U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=b3RcKTVxIL7cc50yhfX9G4YKG3VvnCzDYea6JwkPN5VdoJERtC0cW8VqJ1QvcAC0f im5KD67U7mxPprXHkLcAT/mhoYAWu4/VXo0L0pi5O30alEvZVKx7cmg7cAHaEMsVwk sYeAubqzv8IR3hWb36R83UfvQyiWcErgf/OTH3bHtOLQdmPcyV/4A1LwVlLa2+N28x KgEnU8F+RjwwrxEE5+PJU6iDWuaLzdXefyIyz3Sj/4k57YxslnMDRCdY4uEICTh5ms kGPMEadVVVzKigfHPrIhVi5/PrGWF0ul1q63imJbL6OrWhrQBsFSzx/UtygFC9CCD/ H+givPW1bQ79w== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 04/12] perf jitdump: Bounds-check debug entry byte-swap loop Date: Wed, 5 Aug 2026 18:26:54 -0300 Message-ID: <20260805212704.267779-5-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo The byte-swap loop for JIT_CODE_DEBUG_INFO uses array indexing (jr->info.entries[n]) to iterate debug entries. struct debug_entry has a flexible array member name[], so each entry has a different size. Array indexing computes offsets assuming fixed-size elements, landing inside variable-length name strings after the first entry and byte-swapping garbage. Additionally, nr_entry is read from untrusted jitdump input without validation against total_size, so a crafted value causes OOB reads. Replace the array indexing with debug_entry_next() pointer arithmetic (which correctly accounts for the variable-length name) and bounds-check each entry against the record's total_size before byte-swapping. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 26 ++++++++++++++++++++++---- 1 file changed, 22 insertions(+), 4 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 787f8a03dae87908..078d3304d2b7ebce 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -318,14 +318,32 @@ jit_get_next_entry(struct jit_buf_desc *jd) switch(id) { case JIT_CODE_DEBUG_INFO: if (jd->needs_bswap) { + void *end =3D (void *)jr + jr->prefix.total_size; + struct debug_entry *ent; uint64_t n; + jr->info.code_addr =3D bswap_64(jr->info.code_addr); jr->info.nr_entry =3D bswap_64(jr->info.nr_entry); - for (n =3D 0 ; n < jr->info.nr_entry; n++) { - jr->info.entries[n].addr =3D bswap_64(jr->info.entries[n].addr); - jr->info.entries[n].lineno =3D bswap_32(jr->info.entries[n].lineno); - jr->info.entries[n].discrim =3D bswap_32(jr->info.entries[n].discrim); + + /* + * debug_entry has a variable-length name[], so array + * indexing would compute wrong offsets =E2=80=94 use + * debug_entry_next() and bounds-check each entry. + */ + ent =3D &jr->info.entries[0]; + for (n =3D 0; n < jr->info.nr_entry; n++) { + if ((void *)ent + sizeof(*ent) > end) + break; + /* name must be NUL-terminated within the record */ + if (!memchr(ent->name, '\0', (char *)end - ent->name)) + break; + ent->addr =3D bswap_64(ent->addr); + ent->lineno =3D bswap_32(ent->lineno); + ent->discrim =3D bswap_32(ent->discrim); + ent =3D debug_entry_next(ent); } + /* clamp so downstream consumers don't overrun */ + jr->info.nr_entry =3D n; } break; case JIT_CODE_UNWINDING_INFO: --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 183EF3EB0F2; Wed, 5 Aug 2026 21:27:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965262; cv=none; b=fGifqTAnMFR9ptP/0GtQlYecRXL/feKe7SukVr4MTMsnLRncfdBh6yGfN3gXmoZS/YMcR5EH6rbx2OFxqtunCc0Scdfj2LZPV9+9HcJvPyx/hrpb/Bhkqg4WlNiq81STYKcMsbpLu0hJ10u0f7RDq2vN7GaIvRiP8iOva/NPbCk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965262; c=relaxed/simple; bh=wdvzTd+I7Dt/MCzYRI+XVTtFkks3lV/ZxfZuqNleLjI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ur5VrRivDoB+4TKB8bds+z24scDbYz26LQx9wYY6bVqssSBCBsAzeAVxVgVJ/cfNuIipBZiyvb1mU0Q7yw5aJcA/6GvlWAfJe4rigDuGiRosEvnbO/LqSk8pb8hp2bWGqm01dWpaEJzjkdvStD15fKFhyfWpcyHbHGmuoNfwoF0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=UySGE+U7; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="UySGE+U7" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 36CC21F00A3A; Wed, 5 Aug 2026 21:27:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965260; bh=se3Es46riyeapglgM3WNfK0F1LE8E3A5e3Mgto+pz/o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=UySGE+U7Et/ydmj3PIgegeVKURagCJcvokchIEOal9hJXqxfxYdLJeMH4sIYPsZzB kgfFSry21m1xw5HEDMdJu4XpEyX9z2jIlBP2TRKOPN1BlEmUnxC5Dyz+YY0yj5bTcG g/Q33EHwEgXmp6iV3dFUtUTQLEW+zT2D2aqaETQiJYGpZkiBdpf1aK3KMM9LFSQooz gNF8BWKXCev9121Gr6nUJ5Za+GEOfW84b07CXX5gf0e6ABVJHhZrFkZUP631ckcJLx 98sNq/kaQxWgOLWOckxPaWW00ThSFRmkUlc8idVVN9lwxbvnk5Ie2ufO1hCuyoKXNX 6MYLBzRv5ER0w== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 05/12] perf jitdump: Check snprintf return before computing header size Date: Wed, 5 Aug 2026 18:26:55 -0300 Message-ID: <20260805212704.267779-6-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo snprintf() returns the would-have-been length on truncation. When the jitted filename exceeds PATH_MAX, the unclamped 'size' value inflates sizeof(event->mmap2.filename) - size into a massive underflow, causing the header.size computation to write an oversized header. The subsequent write to 'id =3D event + header.size - idr_size' then corrupts the heap. Clamp size to PATH_MAX - 1 after snprintf in both jit_repipe_code_load() and jit_repipe_code_move(). Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 078d3304d2b7ebce..d7e3dcfc63b78edb 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -493,6 +493,9 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd= , union jr_entry *jr) jd->dir, nspid, count); + /* snprintf returns would-be length on truncation, clamp to buffer */ + if (size >=3D sizeof(event->mmap2.filename)) + size =3D sizeof(event->mmap2.filename) - 1; =20 size++; /* for \0 */ =20 @@ -623,6 +626,9 @@ static int jit_repipe_code_move(struct jit_buf_desc *jd= , union jr_entry *jr) jd->dir, nspid, jr->move.code_index); + /* snprintf returns would-be length on truncation, clamp to buffer */ + if (size >=3D sizeof(event->mmap2.filename)) + size =3D sizeof(event->mmap2.filename) - 1; =20 size++; /* for \0 */ =20 --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 288693F23A1; Wed, 5 Aug 2026 21:27:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965267; cv=none; b=hwZHHTdLP1tvmqqAT9giMzUyJ1yoMbrLK+siT8UhZy5LcVHEOU1ds8QjeWdhIAb/p1xGG/Tk5880IkVlEgDp+CUv+GB140LQ0xwulda2ohkYSi/YldXcPfVlbPFeWry+9BnQGn8rIuXqebzNt9dSOkPqLpaUxGk6BzfmfsjGPVI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965267; c=relaxed/simple; bh=UEl4qGtMSIBxM2UhI/bQTBVn3hKSG5u+HYU4iIIhBK4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=AQDLC6ii8WSqmZMRVrACVAxpDu8daSP3qGu8kThCMQHhceegUwbl6suPkSmmvqUQdhiLwAeUCC2rkzhdpiIz2d9bw4C9soDQotYCOOVyGRfLaihiiihLLgm/R6gcQTuZX/TakGwyS55DK4ZaX64OVWi70mjXHEdxIAukljkRZOo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=f8766jPT; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="f8766jPT" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5405A1F000E9; Wed, 5 Aug 2026 21:27:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965265; bh=vDRzKDjCW+8/V3sFcXtcw+mJHpo2LSPYRAWxzT3h8ew=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=f8766jPTTLnDA8S6UwXMIon+n68BmwYiqZc9GQX4OFqerk8r5on0chCBDtDAkXQOy uFfN5nxkVKGZvb405Nw61YVPWPqXbZOEjUn/So6IypwOTmxiH6XsYM4z5smwlLe2g4 Wm5XiAVp+XSVkkwcns+MdszeGWiUa3BoiYUkiiBHPjdQbxEARvCmWj7wjmkc6jNrB+ 4276v+zB6q/LcfF67keHuFGEQH+jXQ9GAhYwDvDW7blHwqBpCSQ3wR17fQg0D/OvT4 B6EN2za9VxZ0tFWwMKpS3KRjuvxSoaMeg0UAq8aFq/3m6kWJLPPR+vwD/YaPxbi9dd R1wWOA8KKMvog== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 06/12] perf jitdump: Fix funlockfile on unlocked stream in jit_open() error path Date: Wed, 5 Aug 2026 18:26:56 -0300 Message-ID: <20260805212704.267779-7-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo If the malloc() for the initial read buffer fails, jit_open() jumps to the error label which calls funlockfile(jd->in). However, flockfile() is called later in the function, so at this point the stream was never locked. Calling funlockfile() on an unlocked stream is undefined behavior per POSIX. Split the error path into two labels: 'error' (after flockfile) calls funlockfile before cleanup, 'error_noflock' (before flockfile) skips the unlock. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index d7e3dcfc63b78edb..e865a43f6ea8f884 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -155,7 +155,7 @@ jit_open(struct jit_buf_desc *jd, const char *name) =20 buf =3D malloc(bsz); if (!buf) - goto error; + goto error_noflock; =20 /* * protect from writer modifying the file while we are reading it @@ -244,8 +244,9 @@ jit_open(struct jit_buf_desc *jd, const char *name) =20 return 0; error: - free(buf); funlockfile(jd->in); +error_noflock: + free(buf); fclose(jd->in); return retval; } --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93BFA3C13EC; Wed, 5 Aug 2026 21:27:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965272; cv=none; b=foKU9+aoc+TEtk1iV3niFzCIwGcbGB9tyhCTT5mST/adbX1D+/e4E7VSDFxvmitSy64+XapzeacixhPXNNtATfqu40xellnVHZrrsEKAelflV12via7TpjIRLqwH9+jZs1q0Bm7wO4DCTD1LmwCQ/U8CjYTYoqXT+xJ/VHoK6Fg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965272; c=relaxed/simple; bh=gZcEwumJlpFRCvPvjBMaB87q+60D7+O4hVvSDjnIxts=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=iHJtoVhpd9XIB50twrczPpTeovp9MDzqgfcpTml6HEpfGHnfJtyNDfJPPBX9sr7yn1IYhisB06H1U38MYJ2F+LfpK8Jq42S3ULFTXd/ks6hrbzkU/4wbmPRGZs3wx+gF8BVX62CvyWq0MnqsshU14+b1NXm9y+C0gUlekyWwI58= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=bwuxw0Rn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="bwuxw0Rn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 586AF1F00A3A; Wed, 5 Aug 2026 21:27:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965271; bh=+G+AKucJ1isjhdkxWVgPseggtu3KkKfR+/WNxL4KFcs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=bwuxw0RnSa9fYRvJIgR2ixVmLQtJSqfWORRKNvpUpXbKxQi7QttexTdCDthYJuSWd c7lQNinOLewYMi91SBSk4xfxWu3Hc5UtX+nvNqjHfuKhMovFiqN/dL781ZtRpO/9ln J+4RKFWtNwbvXANeoOpvhJ6UbHvEMw/oHugWrF2xlf0bReUddD1h9KJ5GlEk8r4hb6 /6IbMuq4yNA0uSve7tUUO72ES7dRcRoxOOS+q4YCR3K6ttlon9j81TLywp+i804rbV sVuCBg+gq+6e0J+KevmOJLS0sE6xRhtb/skDv6g+2cSmgXjd3bp0L18kTCtj4mdkBN cmL2/pZ/e2kzQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 07/12] perf jitdump: Free event in jit_repipe_code_move() Date: Wed, 5 Aug 2026 18:26:57 -0300 Message-ID: <20260805212704.267779-8-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_repipe_code_move() allocates a perf_event with calloc but never frees it =E2=80=94 the 'out' label exits with only perf_sample__exit(). The sibling function jit_repipe_code_load() correctly calls free(event) at its out label. Add the same free(event) to jit_repipe_code_move(). Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 1 + 1 file changed, 1 insertion(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index e865a43f6ea8f884..f3d9a2b01053a92b 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -683,6 +683,7 @@ static int jit_repipe_code_move(struct jit_buf_desc *jd= , union jr_entry *jr) build_id__mark_dso_hit(tool, event, &sample, jd->machine); out: perf_sample__exit(&sample); + free(event); return ret; } =20 --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 10CAF3F3281; Wed, 5 Aug 2026 21:27:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965278; cv=none; b=RDuknX/beMIy2T3N23yz7m19icZVe7C6yxUJRquQbBL96jb97EGex0GqQUlAK7VaRa3zAJy9+3x8M6HOCQpOvYU+lu8YdBV4x3OOC/Dwenx/xbSPRheH34EwQ1uWui5MkoMoA9qWS8oCa1fThS+7g9FZb9RsnsSsR5iNDQ9zrH4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965278; c=relaxed/simple; bh=78JUD2JGGLuJVO4V85ddsO0NJQ+8ku1lGbYjrMLxD10=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=S2krC3SLDZBgzWx8DW106+VSI+etG3k0T05pX9GbZ+bm05eUbLDUBmlo36Ra12AwSG+sRsiB9Jz4pRhEStcM2TgzyNLjvNxwy++wPJToqALqk+f0BbHgWRa8qtjodhLdhmfmYC0qtovxNX6UR3Mz/KTsiiaA+X4erCCiQOKCxXY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ft5r15Cd; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ft5r15Cd" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D99481F000E9; Wed, 5 Aug 2026 21:27:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965276; bh=DwL11wD1aWkwCZotm9ZScj4gL12D2idG2VplIIApDcA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ft5r15Cd/86z8DT8ScY7TEJ7ueU57pxJU+NsUc7RyH/tL8jvfyKFZBOsL6dHdP2m2 1EQbZnxGJ36vm7u1uZBUxF94s89SoPDe/Crr8RchIaD5urZIsKoti7IVkK0GvWzmEr 4gqGbhxZS3qF3ZP3Haqhu/DPUMDPCL1NgWzI4vm7hwcvt6/OKr21+chhh24qCNJmaW U+EITEcpOexrQ4WM/zjo340QMzH7qpublMTP6kvh3tyO66nY1nHAKqz9rQO+b7gh+/ hgmp7c4nBSC121+qUp5epfYT9k8VoWNyKYPCrFpcPos/pOpzLBE9q2TnyGjvJZjEgH YmtM7BJfOZXWw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 08/12] perf jitdump: Fix debug_data and unwinding_data leaks Date: Wed, 5 Aug 2026 18:26:58 -0300 Message-ID: <20260805212704.267779-9-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_repipe_debug_info() overwrites jd->debug_data without freeing the previous allocation. If two consecutive JIT_CODE_DEBUG_INFO records appear without an intervening LOAD record consuming the data, the first allocation leaks. The sibling jit_repipe_unwinding_info() already frees the old jd->unwinding_data before reassignment =E2=80=94 add the same pattern to jit_repipe_debug_info() using zfree(). Also add cleanup of both buffers in jit_close() so they are freed when the jitdump session ends, even if no LOAD record consumed them. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index f3d9a2b01053a92b..91aa1eea8229faac 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -118,6 +118,8 @@ jit_close(struct jit_buf_desc *jd) funlockfile(jd->in); fclose(jd->in); jd->in =3D NULL; + zfree(&jd->debug_data); + zfree(&jd->unwinding_data); } =20 static int @@ -706,6 +708,7 @@ static int jit_repipe_debug_info(struct jit_buf_desc *j= d, union jr_entry *jr) =20 memcpy(data, &jr->info.entries, sz); =20 + zfree(&jd->debug_data); jd->debug_data =3D data; =20 /* --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2F0821BC2A; Wed, 5 Aug 2026 21:28:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965283; cv=none; b=sqs8UPdl2bDnqhSrbuT30pkXJsS/3EFzwnUTslYs4S0tn1fwqvfKukd93YNJ1iuBCazw3AFCM8bEAHa80sFSmziH8AS577AkDduueGHsZXFM1XGeXOCx4Zp/j4gfLi6bc9jshQvizA0cuBWV/QtxyOEox7R7YJVkQ8SNwk97yfk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965283; c=relaxed/simple; bh=XpzrkI/AxHUiRdfyTzZwu7rrNLNVt1IZLGOuFgGBLvg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=BfWODtZlB7XABzfmvO/N2B93QMq//j9Zof5SRJjuifTLxO17+l9hNxcFa4UgIXoinOmmKWQCyNKHqPxdGftMe2pt/Lk/ueoRETFJmq02nvkCACVIyEJLcTEn2lEvx+wSD5WEffLfR24wUbNF8EoUuCpq7ubhqkOZ7oVlcBHPGy4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=bCLKdUUR; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="bCLKdUUR" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4DE041F00A3A; Wed, 5 Aug 2026 21:27:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965282; bh=46Q32NiiQU+GiIomMs6YY9FirnAhja+ozdHIENQBLbs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=bCLKdUURZsyIIfZZbh/ADlYJHIzpbFz04cmf5fybCSBzjVuMGOBR+vGKaz9nuo718 CPL7GnegNOrxjR2xlQejAUqOZPd/tWjO7qSS1e8zY4wWJviDXRBrrCiMe77/7WtS1K ZYqjzGgaI3ou2WH5m8YCEQHvgrm6dd7pabCnplx+oZdG7B2AVQib1cG/8xSOpNl+9u Wl2oeGRFKyX2mln8dNYicdZMzhI/yGTpqAelnVCGk6SN/dlE+n5uwlej7x6hPsPK3G i11RcpYgD5T1wLjjaXzCAumoKCvbEe6F1Uw/3Zhd7WH2L5mb3t6YL4aIdOn68evF1v nEaKP68z8vWFQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 09/12] perf jitdump: Use dirname() return value in jit_open() Date: Wed, 5 Aug 2026 18:26:59 -0300 Message-ID: <20260805212704.267779-10-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_open() calls dirname(jd->dir) but ignores the return value. POSIX says dirname() may return a pointer to internal static storage =E2=80=94 gl= ibc does this when the path has no '/', returning "." from a static buffer and leaving jd->dir unchanged with the original filename. Capture the return value and copy it back to jd->dir when dirname() returns a different pointer. Fixes: 9b07e27f88b9 ("perf inject: Add jitdump mmap injection support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 91aa1eea8229faac..d3de307532d55065 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -146,6 +146,7 @@ jit_open(struct jit_buf_desc *jd, const char *name) ssize_t bs, bsz =3D 0; void *n, *buf =3D NULL; int ret, retval =3D -1; + char *dname; =20 nsinfo__mountns_enter(jd->nsi, &nsc); jd->in =3D fopen(name, "r"); @@ -241,7 +242,9 @@ jit_open(struct jit_buf_desc *jd, const char *name) */ strncpy(jd->dir, name, PATH_MAX - 1); jd->dir[PATH_MAX - 1] =3D '\0'; - dirname(jd->dir); + dname =3D dirname(jd->dir); + if (dname !=3D jd->dir) + strlcpy(jd->dir, dname, sizeof(jd->dir)); free(buf); =20 return 0; --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 34C4C3EFD21; Wed, 5 Aug 2026 21:28:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965288; cv=none; b=gifuFoRwMSNE/rSNo8vKWp/9Zj7Xxd/5gsjAEL5qQ3NZzju7vq7bzWqeWb6aCmwynbGgr29+7OyZ4wuJz8aeSie9HBV/q6foPdnWz5uAsxYYJKk+oXW+qPJJnbtI2dk6nx37IB8JpbwioU0mal+W3KBr/6whZ46Wx+3KEOSilBg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965288; c=relaxed/simple; bh=XsPXYUoTfryy3R2b7vz0UCgSVVqpijR0pZ48YPHUBAs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=r7mdX8JvThKXvBQzd/iw2rGp/qPUBPiz1JVm7AuV5xhl5NuV9P83z3iE2DRqv79BauEz6fYSRyWQoBiIfo6iubh9PzGeDJ46xC/IWRSXqAQOg4+tnti503iQh90fOoYYY1AEBaPi8mClmeQ638zFNjQPouuRpT6t1tNvMt7+A6I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=YD4rktBy; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="YD4rktBy" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 917CA1F000E9; Wed, 5 Aug 2026 21:28:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965287; bh=uG0bUCcCsV5Kuer6dfyDYUG1djfBK9KIj4YAd8oXHAA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YD4rktBy2sNbWoJK5s0HIjSv0VmXUr7mGYt9Po6OqUWyyRqt+NszGRCclexnHb1oy 87PIMoAUNRYmgFWuNWS14gxSEWniTqZjLW0iJCfs2Aa+pdutA311QnZR5SFYq1wbQM fTX6TXpS+7nXMbMMR353FoFCppW+HjOsAdRvYzNbGKt6Jzpm6acoMAojEMnFMrkB0P /tZRJbwNyHylREWEmAc1//4GZQLmdIOSqr6HWYuO5oT1C9esWnZ+lMNmpf8s+ZEcof P5nk/8EeYH5C9or6CBoiSOev8vxPczQNnaT//8aCCApei0yK4wqjR3sMGMW8BhnNB9 E8mEj3J5okHyA== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 10/12] perf jitdump: Validate debug entries on native (non-swap) path Date: Wed, 5 Aug 2026 18:27:00 -0300 Message-ID: <20260805212704.267779-11-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo The bounds-checking and nr_entry clamping added for the byte-swap path only runs when jd->needs_bswap is true. On native-endian files, nr_entry passes through unvalidated to jit_repipe_debug_info(), which stores it as jd->nr_debug_entries. Downstream, jit_process_debug_info() in genelf_debug.c iterates nr_debug_entries times via debug_entry_next(), which calls strlen() on each entry's name field =E2=80=94 a crafted nr_entry causes OOB reads and writes. Add bounds-checked iteration in jit_repipe_debug_info() that validates each debug_entry fits in the payload and its name is NUL-terminated before calling debug_entry_next(). Clamp nr_debug_entries to the count of valid entries. Fixes: 598b7c6919c7bbcc ("perf jit: add source line info support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 27 ++++++++++++++++++++++----- 1 file changed, 22 insertions(+), 5 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index d3de307532d55065..5a3ea2681fb37105 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -694,8 +694,10 @@ static int jit_repipe_code_move(struct jit_buf_desc *j= d, union jr_entry *jr) =20 static int jit_repipe_debug_info(struct jit_buf_desc *jd, union jr_entry *= jr) { - void *data; - size_t sz; + struct debug_entry *ent; + void *data, *end; + size_t sz, valid; + uint64_t i; =20 if (!(jd && jr)) return -1; @@ -715,10 +717,25 @@ static int jit_repipe_debug_info(struct jit_buf_desc = *jd, union jr_entry *jr) jd->debug_data =3D data; =20 /* - * we must use nr_entry instead of size here because - * we cannot distinguish actual entry from padding otherwise + * Clamp nr_debug_entries to entries that actually fit in the + * payload. The byte-swap path already does this for cross-endian + * files; validate on the native path too, since downstream + * jit_process_debug_info() iterates via debug_entry_next() which + * calls strlen() on each entry's name field. */ - jd->nr_debug_entries =3D jr->info.nr_entry; + end =3D data + sz; + ent =3D data; + valid =3D 0; + for (i =3D 0; i < jr->info.nr_entry; i++) { + if ((void *)ent + sizeof(*ent) > end) + break; + /* name must be NUL-terminated within the payload */ + if (!memchr(ent->name, '\0', (char *)end - ent->name)) + break; + ent =3D debug_entry_next(ent); + valid++; + } + jd->nr_debug_entries =3D valid; =20 return 0; } --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D77743ED10F; Wed, 5 Aug 2026 21:28:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965294; cv=none; b=iKVh4tIsBKSDdPUanOxnb+uWN8ivtqfF/cJiN+kd7C4fsFqekyBY/DEO/x6/Psss5J6DOLnBJL4Q/Rqc+tYzv8CMtPaW0EaDsJ85JcWvmKtUvQR1fzobJpcXGgQXYW0WnUnLTL3zPB1e/5V9n0/tj5wypSwoQ+MND2+a9M3mNjE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965294; c=relaxed/simple; bh=SZQuzrP/ehv3y8PwjY5jperLSL3kBkBVUroC8jwdI3s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LGFNbj73i4S5vFrF5inFLQFxj175w4I9sTRVLe7c0gzP25Pl5fD8GjNTDU4rP2rnKTPEd2DnmZ77CgcYc5zKSI5EBJpuyWmPgmAnffIbIzTlCdklv8FmbDdjIjmD4WkBt5hY1MtkBPNX61CaNwxXgiDRWq14HJaOVvKYoXdipxU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=oCifNleg; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="oCifNleg" Received: by smtp.kernel.org (Postfix) with ESMTPSA id BA7291F00A3A; Wed, 5 Aug 2026 21:28:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965292; bh=RUyxmj3vxNdvlR8l7JK2MtQk0vGO/OK+dQDKwAGY5Bw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oCifNlegBDQFTaomFnstyVvnkPAKjRPveAPbQfAZtxSlMCq44cBuid7ZIuON3w9cw sa7w7+MHpyoV1ojXdd98zFhWJ+Wbf+EbRGD7xbHIdd2X/0tcaNu58+z7xnuciuhH49 GUkfvNUawHrSgtyrzJPQnc984CH2TLA4pOpS160EU9KQsUroJM9HSe2SL+RR8qQhBw tL4NESueckPk0GHaaTsy+ODtgE0VmUL5/GXAFXhv+67WVA3s3agMfIkWhUB64tUc0/ qOetCcLdoIWCrrh9szIjGT+5lKzvKUFbZVbbm4SyeU65lpp6une8onrz96t4gvOidB Z4JHMSNoEfMWw== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stephane Eranian Subject: [PATCH 11/12] perf jitdump: Validate sym string NUL-termination in code load Date: Wed, 5 Aug 2026 18:27:01 -0300 Message-ID: <20260805212704.267779-12-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Arnaldo Carvalho de Melo jit_repipe_code_load() computes sym =3D (void *)jr + sizeof(jr->load) and passes it to jit_emit_elf() which calls strlen(sym) via jit_write_elf(). If code_size equals total_size - sizeof(jr->load), the sym pointer aliases the code blob with no NUL terminator, and strlen() scans past the buffer into adjacent heap memory. Add a memchr() check to verify the symbol name is NUL-terminated within the region between the load header and the code blob before use. Fixes: 598b7c6919c7bbcc ("perf jit: add source line info support") Reported-by: sashiko-bot Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 5a3ea2681fb37105..5898a7d8eb962daf 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -487,6 +487,13 @@ static int jit_repipe_code_load(struct jit_buf_desc *j= d, union jr_entry *jr) =20 sym =3D (void *)((unsigned long)jr + sizeof(jr->load)); code =3D (unsigned long)jr + jr->load.p.total_size - csize; + + /* sym string lives between the load header and the code blob */ + if (!memchr(sym, '\0', code - (unsigned long)sym)) { + pr_warning("jitdump: unterminated symbol name in code_load record\n"); + return -1; + } + count =3D jr->load.code_index; idr_size =3D jd->machine->id_hdr_size; =20 --=20 2.55.0 From nobody Sat Oct 3 03:52:45 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9949E3F211A; Wed, 5 Aug 2026 21:28:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965300; cv=none; b=Hb3vdmcU2KCLK9do4Exl2eiy+d0hooD7R2ulPHMxwuuFYpf9PwMOlT0qs5/JCG12bmxhwsnYJ8qhh7bt/PKz1GxBYkYSHgTpA9nhJjvSvrbA1RVp9WFthzcX3OaBtMbHb/8U7X8UUMf8P2LTmoL5H0d8o+RAbLdY5LRAsfLN3LQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785965300; c=relaxed/simple; bh=BMSZSbh4QqCDcAj4jNHr9AUogJVXdKpevF2vPUwfF7g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=RcDWywqE9VxqeSHK4Y99WBw9l+9l35I50mcoa2rzGMWaOHkSKqii3AZ+3lrDq8u8JaSzqJx33Pp3Zw0MDdi9I4l4Gxtt47G60XyacbzzpmeyxnXCAZp7CpYkwojvBfAWpr1sgCLRzPhrTsobe10i85KNatrGj4LcgIZdsubwQh0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Gz9KsmHW; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Gz9KsmHW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 160DB1F00A3D; Wed, 5 Aug 2026 21:28:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785965298; bh=jz8pdtxPjlYzX8D8R/3BRdPfTaskLXym80/LcGKzffs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Gz9KsmHW7SXb3wtPtBcKPpFLuJjjg7J/tswEQQpqKKJz2WxSrU2+47Qke28jOXE4g SN0YRB7wqMpyW+oVlhBSLD+3dXjFimggaJ6L4VFFkWxx23WbdJRXHikPRColfz6YfK MqI+vGXkV+fFZuDM1NxlygL/2mvlmt6mMRNkjT8yJkTHVzAKWDTxH0qrbexVFR6HTt 4vhm3xCRB/Iz3N+ebHpmt4ET0W3fsP6HPI3X7RVOMzUfBKwvmi6HuVosMa00DCOz8r rGeW7P54YWp7lh+J/DEa46W5smr4g+0lQ0kjf2qqy3tGnvqrwafqy6UWY1iTSoe4Mw qLRDxAxMXVFtQ== From: Arnaldo Carvalho de Melo To: Namhyung Kim Cc: Ingo Molnar , Thomas Gleixner , James Clark , Jiri Olsa , Ian Rogers , Adrian Hunter , Clark Williams , linux-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Arnaldo Carvalho de Melo , sashiko-bot , Stefano Sanfilippo , Stephane Eranian Subject: [PATCH 12/12] perf jitdump: Validate unwinding sizes against record payload Date: Wed, 5 Aug 2026 18:27:02 -0300 Message-ID: <20260805212704.267779-13-acme@kernel.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260805212704.267779-1-acme@kernel.org> References: <20260805212704.267779-1-acme@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Arnaldo Carvalho de Melo jit_repipe_unwinding_info() copies unwinding_size and eh_frame_hdr_size from the jitdump record into jd-> fields without checking them against the actual payload size. Downstream, jit_add_eh_frame_info() in genelf.c computes unwinding_table_size =3D unwinding_size - eh_frame_hdr_size, which underflows when eh_frame_hdr_size > unwinding_size. The result is passed as d->d_size to libelf, causing an OOB heap read into the output ELF file. Validate that unwinding_size fits within the record payload and that eh_frame_hdr_size does not exceed unwinding_size before allocating or storing the values, so a bogus record cannot force a large allocation that is then discarded. mapped_size is likewise taken from the record and was narrowed into an int for the mmap2 len computation in jit_repipe_code_load() and jit_repipe_code_move(); values above INT_MAX would turn negative, producing a wrong mmap2 length. Use uint64_t for usize so the value cannot truncate. Fixes: 0284fecd13b6db3e ("perf jit: Add unwinding support") Reported-by: sashiko-bot Cc: Stefano Sanfilippo Cc: Stephane Eranian Assisted-by: Claude:claude-opus-4.6 Assisted-by: Opencode:mimo-v2.5-free Reviewed-by: Ian Rogers Signed-off-by: Arnaldo Carvalho de Melo --- tools/perf/util/jitdump.c | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c index 5898a7d8eb962daf..d25a9fe9b020ce87 100644 --- a/tools/perf/util/jitdump.c +++ b/tools/perf/util/jitdump.c @@ -462,7 +462,8 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd= , union jr_entry *jr) u16 idr_size; const char *sym; uint64_t count; - int ret, csize, usize; + int ret, csize; + uint64_t usize; pid_t nspid, pid, tid; struct { u32 pid, tid; @@ -543,7 +544,7 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd= , union jr_entry *jr) =20 event->mmap2.pgoff =3D GEN_ELF_TEXT_OFFSET; event->mmap2.start =3D addr; - event->mmap2.len =3D usize ? ALIGN_8(csize) + usize : csize; + event->mmap2.len =3D usize ? ALIGN_8((uint64_t)csize) + usize : (uint64= _t)csize; event->mmap2.pid =3D pid; event->mmap2.tid =3D tid; event->mmap2.ino =3D st.st_ino; @@ -612,7 +613,7 @@ static int jit_repipe_code_move(struct jit_buf_desc *jd= , union jr_entry *jr) char *filename; size_t size; struct stat st; - int usize; + uint64_t usize; u16 idr_size; int ret; pid_t nspid, pid, tid; @@ -761,6 +762,18 @@ jit_repipe_unwinding_info(struct jit_buf_desc *jd, uni= on jr_entry *jr) return -1; =20 unwinding_data_size =3D jr->prefix.total_size - sizeof(jr->unwinding); + + /* + * Validate sizes before allocating =E2=80=94 jit_add_eh_frame_info() + * computes unwinding_size - eh_frame_hdr_size and uses the + * result as a buffer length for libelf. + */ + if (jr->unwinding.unwinding_size > unwinding_data_size || + jr->unwinding.eh_frame_hdr_size > jr->unwinding.unwinding_size) { + pr_warning("jitdump: invalid unwinding sizes in unwinding_info record\n"= ); + return -1; + } + unwinding_data =3D malloc(unwinding_data_size); if (!unwinding_data) return -1; --=20 2.55.0