From nobody Mon Sep 28 08:55:48 2026 Received: from mail-oi2-f11.google.com (mail-oi2-f11.google.com [74.125.231.203]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C59D2372B2B for ; Mon, 24 Aug 2026 10:20:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.231.203 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787566839; cv=none; b=mb3F/J2QzU9WEGZu+G2w5HWnOuOe9Qyme+/toqDslJPMszrt7lnZoejvUUUUzNg7/oIWpbx7MpPevEu3QxUqSc6YU+mNBY0GGzy2TSVr91FMMyrVb6ZKwmfRLX7SqM7+eghIHpUEfQS4Cj0e6R0Y8V3nPXNQ1ymiU0ruv283HlI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787566839; c=relaxed/simple; bh=lPPVGAstHmikN1GkkMpgs5o8PyqaxuXluMd9NmQb03E=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Kowm2WGtmCni9F4CgldL9N6qqdrtqJ7EuLVZwvmmXnpQHyEYGVCw0gm7jKv5v4toNUqriwbrkwlQ3P/0cJaraW47OLI39Iy6A+IVDFl89JrofIvc1X+4TAWZJSeNc/+zbh2c+LGe2q0ZVGT9dbLCbSFVj5Wk0GAWpN0suoDqaZc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PBSOT47c; arc=none smtp.client-ip=74.125.231.203 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PBSOT47c" Received: by mail-oi2-f11.google.com with SMTP id 5614622812f47-4b25c60f07cso1274055b6e.1 for ; Mon, 24 Aug 2026 03:20:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787566837; x=1788171637; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=z5aZlHmDHOQxmVbZgRFaFqVNVR5nPWlfPpl37pEOfY0=; b=PBSOT47cQzpJ5p+SCeaD/fQ+BKMwlXxSzezvvKNBsoPHYIEuikuAdxbrTlDqbphIzP ZSnq9HkHv3mpStVONCo/shjMbc1YrMYc43YRLMPIF64uPMqQDpSe79D1gcGABXYWKKvd v2wmQeZWot+Uel9yqn0Ivz7PpqG19GyoWLnVYxI8bGx7HkSv2wtgZdUhbD5rQB/TY+t4 kLni/PlVfrEnwFdUTpZfAUR1V/Fvq0jeccbMvbV/YpARbxItYTasnECRlyARsrwj9tPa NoJvaXSu7c38YSIU7h8pZ6jqxdWT8yq0WSKFls+hDQaoiHI0MY8yAKDlQ+x0qLr8KzCd pfHg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787566837; x=1788171637; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=z5aZlHmDHOQxmVbZgRFaFqVNVR5nPWlfPpl37pEOfY0=; b=sfwQkG8RqJhnFeJTY8+O/wE9EHi0oq1ijbUddH52Mnj0dgsRA9V9ZOe9gVavmtqKWl DFQ0j3+bvoQ/xMr3FFMla3pnAXv7LZGOKAIuhswFSk5gLGBlkIEWs3LhY+cdeubKeecz 7JO2x0In7fMcVXbCIfKbC/l3GnJHTmst17lPtTnNDTa8g/XxqtbUDLJUNYD6IBdHQ5k5 UNPXyOHD45s6wy34YfB00+CQCOSSLGznsa1qhwE9uMYZiQm2k2kPKEUCfFXIk4heIBg4 WNnBxnsz2Z+UlUGts3dtZSjkiLvLO9HzVTf78UqScHH1KxLGekreeZ8F2MBH/ZhGFtQi mOYw== X-Forwarded-Encrypted: i=1; AHgh+RpJI2D1fEcvsRh25LnHH/nq26uqQA3TirZ6tp/aEhn5E5Je5TMLuf3/wEqzhEx9t3Q78Z7Nr58EBYYsmdA=@vger.kernel.org X-Gm-Message-State: AFuF++nWP3bVmp4R86JoXGoG/NGy3Rg0AAScUY4pgCkY7n2brnf3UJ+v 0GERQyh/hy1rhZ7SBueLtTUluYDlC1vf6Jjcl2ShH9hiY0QynL3UQpupiXj4SBcebc4= X-Gm-Gg: AR+sD13QpJ3A+LP2R2TvGbMt9DuGXJI11JvkBoojT/jRECxwOS53RUel+J1ROwe1xcq dY7nvjrJfFfBqYs10sckYk9U7gHMRnjRNPvCiZpq9/j7y09yeTx4Mg9Q25yI6NrXFCFE47B6C/A ii/OsnKAG3TcI4i1uTPcz+S6PTSrOVq6y5tkUsqv6TSM2tXrESyUmDuilYBp6AjaG1mJrJBYOWO b5rX9rJRkRJQgaIuE1gAOxC9ggSXTzIIgpM7VwBHruVXGv0cALDpPOT5MslFxw+AxKjvdvZSQmo MMhH+wEhE187DOgpMdgT2RcX9yt8dp4I9i6j7ivK++19HCquIGo9TDpR5GN7FUGNM5U+B2Op3A+ EmvJ/m6LiUKMcnK00mg7eCYLyvf8Bg++ZPX5glAxx287oMcBZFobfi97YTm0kFhr0eyBKv50KHx 1oy/LeKkcnM1uF/m/CG3V8z48nMk3hXrG7PlIQrvbd0BRuSsrItEj20dtNMMdcqiPxpqLG/hn3c 6grVT2385wtMpuuIIN71RHHO4A= X-Received: by 2002:a05:6820:20e:b0:6aa:de29:651 with SMTP id 006d021491bc7-6b159294dfemr25899528eaf.16.1787566836558; Mon, 24 Aug 2026 03:20:36 -0700 (PDT) Received: from localhost.localdomain ([14.116.239.36]) by smtp.gmail.com with ESMTPSA id 006d021491bc7-6b17c703cf8sm3535763eaf.0.2026.08.24.03.20.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 03:20:35 -0700 (PDT) From: Henry Martin To: Steven Rostedt , Masami Hiramatsu Cc: Mathieu Desnoyers , linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org, Henry Martin Subject: [PATCH v2] tracing: Fix use-after-free on field name/type of dynamic probe events Date: Mon, 24 Aug 2026 18:20:29 +0800 Message-ID: <20260824102029.4132962-1-bsdhenrymartin@gmail.com> X-Mailer: git-send-email 2.43.7 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fields of a probe-based dynamic event (kprobe, uprobe and eprobe events) are created from the argument name and type strings of the trace_probe that first registers the event, as plain pointer references without copying. When several probes are appended to the same event, they share the trace_event_call and its field list, which stays the one defined by the primary probe. Deleting just the primary probe with "-:group/event symbol" frees the trace_probe and its argument strings, while the event call is kept registered by the remaining sibling probes. field->name and field->type are left dangling, and any field lookup - e.g. writing to events///filter - reads freed memory: BUG: KASAN: slab-use-after-free in strcmp+0xa7/0xb0 Call trace: trace_find_event_field+0xd6/0x220 parse_pred process_preds create_filter apply_event_filter event_filter_write Make the field own its strings: duplicate name and type with kstrdup_const() in __trace_define_field() and release them with kfree_const() in trace_destroy_fields(). Fields of built-in trace events still reference their kernel rodata string literals directly, as kstrdup_const()/kfree_const() only touch memory that was actually allocated. Module trace events pay one extra copy per string, since module rodata is outside the core kernel rodata range checked by is_kernel_rodata(); the copy also makes field strings immune to module unload edge cases (e.g. forced unload) where the module text may be freed while its trace event structures are still referenced. The issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab. Fixes: ca89bc071d5e4 ("tracing/kprobe: Add multi-probe per event support") Signed-off-by: Henry Martin --- v2: Clarify in the commit message that module rodata strings are duplicated rather than referenced (kstrdup_const() checks only the core kernel rodata range), and scope the module-unload benefit to edge cases rather than the normal removal path, which already tears down module events via the module notifier. kernel/trace/trace_events.c | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/kernel/trace/trace_events.c b/kernel/trace/trace_events.c index c01b10b99f67e..ee3b93fa09ee8 100644 --- a/kernel/trace/trace_events.c +++ b/kernel/trace/trace_events.c @@ -123,8 +123,18 @@ static int __trace_define_field(struct list_head *head= , const char *type, if (!field) return -ENOMEM; =20 - field->name =3D name; - field->type =3D type; + field->name =3D kstrdup_const(name, GFP_TRACE); + if (!field->name) { + kmem_cache_free(field_cachep, field); + return -ENOMEM; + } + + field->type =3D kstrdup_const(type, GFP_TRACE); + if (!field->type) { + kfree_const(field->name); + kmem_cache_free(field_cachep, field); + return -ENOMEM; + } =20 if (filter_type =3D=3D FILTER_OTHER) field->filter_type =3D filter_assign_type(type); @@ -225,6 +235,8 @@ static void trace_destroy_fields(struct trace_event_cal= l *call) head =3D trace_get_fields(call); list_for_each_entry_safe(field, next, head, link) { list_del(&field->link); + kfree_const(field->name); + kfree_const(field->type); kmem_cache_free(field_cachep, field); } } --=20 2.43.0