tools/perf/util/powerpc-vpadtl.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
min_sz is set to sizeof(u64) * POWERPC_VPADTL_TYPE, but the code reads
auxtrace_info->priv[POWERPC_VPADTL_TYPE], which needs at least
POWERPC_VPADTL_TYPE + 1 elements. POWERPC_VPADTL_TYPE is the first
enumerator of the priv index enum (0), so min_sz evaluates to 0 and the
check validates only the perf_record_auxtrace_info header itself. A
PERF_RECORD_AUXTRACE_INFO event carrying a zero-length priv array then
passes the size check, and the subsequent priv[POWERPC_VPADTL_TYPE]
read runs one u64 past the validated region.
This is the same off-by-one fixed for Intel PT by commit c4362d5e1a5e
("perf intel-pt: Fix off-by-one in auxtrace_info minimum size check")
and for Intel BTS by commit b9fb8225951c ("perf intel-bts: Fix off-by-one
in auxtrace_info minimum size check").
Use sizeof(u64) * (POWERPC_VPADTL_TYPE + 1) so the highest accessed
priv index is covered by the minimum-size validation.
Fixes: c4bbd4ec2e50 ("perf powerpc: Process auxtrace events and display in 'perf report -D'")
Cc: stable@vger.kernel.org
Signed-off-by: Wang Yan <wangyan01@kylinos.cn>
---
tools/perf/util/powerpc-vpadtl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/perf/util/powerpc-vpadtl.c b/tools/perf/util/powerpc-vpadtl.c
index 710f3093f3f9..c15636eef34b 100644
--- a/tools/perf/util/powerpc-vpadtl.c
+++ b/tools/perf/util/powerpc-vpadtl.c
@@ -683,7 +683,7 @@ int powerpc_vpadtl_process_auxtrace_info(union perf_event *event,
struct perf_session *session)
{
struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
- size_t min_sz = sizeof(u64) * POWERPC_VPADTL_TYPE;
+ size_t min_sz = sizeof(u64) * (POWERPC_VPADTL_TYPE + 1);
struct powerpc_vpadtl *vpa;
int err;
--
2.25.1
On 24/08/2026 05:55, Wang Yan wrote:
> min_sz is set to sizeof(u64) * POWERPC_VPADTL_TYPE, but the code reads
> auxtrace_info->priv[POWERPC_VPADTL_TYPE], which needs at least
> POWERPC_VPADTL_TYPE + 1 elements. POWERPC_VPADTL_TYPE is the first
> enumerator of the priv index enum (0), so min_sz evaluates to 0 and the
> check validates only the perf_record_auxtrace_info header itself. A
> PERF_RECORD_AUXTRACE_INFO event carrying a zero-length priv array then
> passes the size check, and the subsequent priv[POWERPC_VPADTL_TYPE]
> read runs one u64 past the validated region.
>
> This is the same off-by-one fixed for Intel PT by commit c4362d5e1a5e
> ("perf intel-pt: Fix off-by-one in auxtrace_info minimum size check")
> and for Intel BTS by commit b9fb8225951c ("perf intel-bts: Fix off-by-one
> in auxtrace_info minimum size check").
>
> Use sizeof(u64) * (POWERPC_VPADTL_TYPE + 1) so the highest accessed
> priv index is covered by the minimum-size validation.
>
> Fixes: c4bbd4ec2e50 ("perf powerpc: Process auxtrace events and display in 'perf report -D'")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wang Yan <wangyan01@kylinos.cn>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
> ---
> tools/perf/util/powerpc-vpadtl.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tools/perf/util/powerpc-vpadtl.c b/tools/perf/util/powerpc-vpadtl.c
> index 710f3093f3f9..c15636eef34b 100644
> --- a/tools/perf/util/powerpc-vpadtl.c
> +++ b/tools/perf/util/powerpc-vpadtl.c
> @@ -683,7 +683,7 @@ int powerpc_vpadtl_process_auxtrace_info(union perf_event *event,
> struct perf_session *session)
> {
> struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
> - size_t min_sz = sizeof(u64) * POWERPC_VPADTL_TYPE;
> + size_t min_sz = sizeof(u64) * (POWERPC_VPADTL_TYPE + 1);
> struct powerpc_vpadtl *vpa;
> int err;
>
On Mon, Aug 24, 2026 at 08:55:52AM +0300, Adrian Hunter wrote:
> On 24/08/2026 05:55, Wang Yan wrote:
> > min_sz is set to sizeof(u64) * POWERPC_VPADTL_TYPE, but the code reads
> > auxtrace_info->priv[POWERPC_VPADTL_TYPE], which needs at least
> > POWERPC_VPADTL_TYPE + 1 elements. POWERPC_VPADTL_TYPE is the first
> > enumerator of the priv index enum (0), so min_sz evaluates to 0 and the
> > check validates only the perf_record_auxtrace_info header itself. A
> > PERF_RECORD_AUXTRACE_INFO event carrying a zero-length priv array then
> > passes the size check, and the subsequent priv[POWERPC_VPADTL_TYPE]
> > read runs one u64 past the validated region.
> >
> > This is the same off-by-one fixed for Intel PT by commit c4362d5e1a5e
> > ("perf intel-pt: Fix off-by-one in auxtrace_info minimum size check")
> > and for Intel BTS by commit b9fb8225951c ("perf intel-bts: Fix off-by-one
> > in auxtrace_info minimum size check").
> >
> > Use sizeof(u64) * (POWERPC_VPADTL_TYPE + 1) so the highest accessed
> > priv index is covered by the minimum-size validation.
> >
> > Fixes: c4bbd4ec2e50 ("perf powerpc: Process auxtrace events and display in 'perf report -D'")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Wang Yan <wangyan01@kylinos.cn>
>
> Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Thanks, applied to perf-tools-next, for v7.4.
- Arnaldo
© 2016 - 2026 Red Hat, Inc.