From nobody Mon Sep 28 23:55:42 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4C7ED3CF699; Fri, 14 Aug 2026 14:49:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786718948; cv=none; b=RkFYR2BTsX2seYd+kp7eNbyT5gxkIvNfDBHGUEgC4HKQCvptqpZorcMyewjxIMHMZwpun7MrydPEmzl9v2DU1LEURiIe8wLVvAYxQhv3D9YAKeBXDu1FhNuhFLgLAfT+z+M9d+juHPu6DE/642y6YGf+rCBN/Oq51/UuRO6Di6w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786718948; c=relaxed/simple; bh=7+bN1TZKacyRXechISZSOSGjlg9FX4uJDoaorVRA2fU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EIHEzCKokThw6TB3gntnRt1va7lOOqRvvCdr394gQ4iH+zcH1ifc3lXXzY1qFnIIoZoQGfUNlzSqnJ7GMbzSBtDtI6OH16CPCXfTMynLJuD/UGwB1s1x6edVgBSLdd8R+HgEWP9WuO+t6+xJNrQletSFalsHz1bK8f3Lzdzx1tc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=oc0XcM0X; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=j2OuR/0r; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="oc0XcM0X"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="j2OuR/0r" From: Sebastian Andrzej Siewior DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1786718943; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=SK6erdxfE4Myh29DN+Y5TS6R4dais4jnxoRvV8jJ/zw=; b=oc0XcM0XE6lczZIpqt2JXeEPvFfzXnx3pKKWXE02fSWOLPPozKeatKQ3fMxusZL4ONnwXN VC/kcfg3ddA4E4qc+O9oW/fmAWiJ4IxAPDzUuYdM6QdwOjOEx+KF1djhqkb+FIXx7uiEZz japESG6GwK+6vCrQD49dWzEwrgjLdXzAhNYdjW79tLiKkjQxg1AQgNdGQ/rSGewYlhRmbD TPQptQYLYb3aNGhbt4p94YEwJdtFH4G1LcVTdW5mN7AO0s1leIUvl/1q84kxTOdnJqdEIQ qLG7LwWX4txROqh1++0PBMOXTSYYsfKUJ11U+EOMcaxN5VXr0zduhsNWnrUoSA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1786718943; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=SK6erdxfE4Myh29DN+Y5TS6R4dais4jnxoRvV8jJ/zw=; b=j2OuR/0rWy4/6Ik2fZmGbUNBz68uPfEKuyWGKlvkmUiA1Wo1VOGmoAfy3+Ce4WbMU8eOY2 IdUKeesaTrvkhhCg== To: linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org Cc: Andrew Morton , Andy Shevchenko , Kees Cook , Petr Mladek , Rasmus Villemoes , Sergey Senozhatsky , Steven Rostedt , Tycho Andersen , Sebastian Andrzej Siewior Subject: [PATCH 1/2] vsprintf: Don't leak pointers for %ps without KALLSYMS enabled Date: Fri, 14 Aug 2026 16:48:53 +0200 Message-ID: <20260814144854.746840-2-bigeasy@linutronix.de> In-Reply-To: <20260814144854.746840-1-bigeasy@linutronix.de> References: <20260814144854.746840-1-bigeasy@linutronix.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The "%ps" format modifier prints the name of the symbol which is more valuable in terms of debugging and does not leak the actual pointer. Without KALLSYMS it will leak the pointer which is not intended. The default policy for pointers is to print a hashed value and not to leak the actual pointer. Print "(unknown)" for any symbol resolution witout KALLSYMS enabled. Signed-off-by: Sebastian Andrzej Siewior --- lib/vsprintf.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/vsprintf.c b/lib/vsprintf.c index 2bc6ef483576c..ac954cc7bfb31 100644 --- a/lib/vsprintf.c +++ b/lib/vsprintf.c @@ -1008,7 +1008,7 @@ char *symbol_string(char *buf, char *end, void *ptr, =20 return string_nocheck(buf, end, sym, spec); #else - return special_hex_number(buf, end, value, sizeof(void *)); + return string_nocheck(buf, end, "(unknown)", spec); #endif } =20 --=20 2.55.0 From nobody Mon Sep 28 23:55:42 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5942E47424E; Fri, 14 Aug 2026 14:49:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786718949; cv=none; b=nkw7SHUKBVZtuhqtyTX3FR33WD7vQAJo3PwqhFCLsfiO9B4jCmVzxGA2w+KTecX+zXZ6QhAHrSb3XfRZIX+iRCcfHlyPO8Gyn2AJGZRlX4LZ8jDy9bKAAf6QJ+mtu3H7jOhX1i7sufHnUlKLZ1No2kYzNcU7FYBnydl2SWnbS+Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786718949; c=relaxed/simple; bh=+fr8RZV46XEy8wVWiO+AhrOJCq+xb5t13cxpCF74HcM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=DNaninF+8NdrYD170aFFL9rRVDSObZPmiQjxL9CWtLWlGyrXJ8WfpslTuD972v1VysJPxSwhc8lP8MMKP8yL/KRWcP2TE6t/wyqHQJ6Y2zZkpsc/ZHNXa8YhRt6Uf2txaPCGhGLML7zcSauFUX59U9KwNV+hv5zLEGqUXIWhwCI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=apjYaTeR; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=p8OlBoZQ; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="apjYaTeR"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="p8OlBoZQ" From: Sebastian Andrzej Siewior DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1786718943; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=lXsO7Tw5Jdt32cHEwQa9lZY39lvveuyKQYw9Bls8lWM=; b=apjYaTeRIS0F3OcLEe65pOi5KvAKDraVw2rIxhdr4PQByIk9a0LBQKlJ29msrBThllxdPr zjdEzLzw4S3cmlyfonPPzyjQq8id215rveWHbvPvYpuA2t8qX3oohDqCZHsftH/3NuWFrt f07URECsuHxnhcCNU5DPwMdMoMhTzFg2M8949jLRbJgU59bWsgPz/CWDcjtyavebiM5M+9 irNWw4KovF/3Y1xppKR6dJeJQwVUrsxJtKCNpYnqP0GbrocCsct4WaWVAF1KOGrIZHLAhT flywx6Q0lvBihOeazbMvg0FgXarYZK3oMvNIluBJhfUvyHbzZ5dvZhjX1kIVnA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1786718943; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=lXsO7Tw5Jdt32cHEwQa9lZY39lvveuyKQYw9Bls8lWM=; b=p8OlBoZQpXi/thDkqOFA69RXjTlQTzKbAlW611bVdodcMKKNFHQwemvixP1uVD8TgzFNGY YQUTRgGR+JVxRQAQ== To: linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org Cc: Andrew Morton , Andy Shevchenko , Kees Cook , Petr Mladek , Rasmus Villemoes , Sergey Senozhatsky , Steven Rostedt , Tycho Andersen , Sebastian Andrzej Siewior , Namhyung Kim Subject: [PATCH 2/2] kallsyms: Don't leak pointers for unresolved symbols. Date: Fri, 14 Aug 2026 16:48:54 +0200 Message-ID: <20260814144854.746840-3-bigeasy@linutronix.de> In-Reply-To: <20260814144854.746840-1-bigeasy@linutronix.de> References: <20260814144854.746840-1-bigeasy@linutronix.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" __sprint_symbol() is supposed to resolve the passed address to a symbol name. If the symbol can not be resolved it will print the actual pointer that was passed. The pointer policy is to not reveal actual pointer values. Backtraces used to print the address followed by the symbol name. The address has been removed leaving just the resolved symbol. If the pointer can not be resolved to a symbol, it shouldn't be printed as the bare value. Print "(unknown)" for any symbol that can not be resolved. Cc: Namhyung Kim Signed-off-by: Sebastian Andrzej Siewior Reviewed-by: Bradley Morgan # kernel/ --- kernel/kallsyms.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/kallsyms.c b/kernel/kallsyms.c index aec2f06858afd..c70adaa97c24b 100644 --- a/kernel/kallsyms.c +++ b/kernel/kallsyms.c @@ -483,7 +483,7 @@ static int __sprint_symbol(char *buffer, unsigned long = address, len =3D kallsyms_lookup_buildid(address, &size, &offset, &modname, &build= id, buffer); if (!len) - return sprintf(buffer, "0x%lx", address - symbol_offset); + return sprintf(buffer, "(unknown)"); =20 offset -=3D symbol_offset; =20 --=20 2.55.0