mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
perf dso: Replace assert with runtime check in dso__read_symbol()
dso__read_symbol() asserts that len <= jited_prog_len, where len comes
from sym->end - sym->start (parsed from PERF_RECORD_KSYMBOL in
perf.data). Both values originate from untrusted file input.
With NDEBUG (production builds), the assert is compiled out, allowing
an out-of-bounds heap read when the BPF program buffer is accessed.
Without NDEBUG, a crafted perf.data crashes perf with an assertion
failure.
Replace the assert with a runtime bounds check that returns NULL with
an appropriate error code, matching the existing error handling
pattern in this function.
Fixes: aa04707f50 ("perf dso: Support BPF programs in dso__read_symbol()")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Song Liu <song@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
This commit is contained in:
parent
390a9461cd
commit
62972e5644
|
|
@ -2038,7 +2038,12 @@ const u8 *dso__read_symbol(struct dso *dso, const char *symfs_filename,
|
|||
errno = SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF;
|
||||
return NULL;
|
||||
}
|
||||
assert(len <= info_linear->info.jited_prog_len);
|
||||
if (len > info_linear->info.jited_prog_len) {
|
||||
pr_debug("BPF symbol length %zu exceeds jited_prog_len %u\n",
|
||||
len, info_linear->info.jited_prog_len);
|
||||
errno = SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF;
|
||||
return NULL;
|
||||
}
|
||||
*out_buf_len = len;
|
||||
return (const u8 *)(uintptr_t)(info_linear->info.jited_prog_insns);
|
||||
#else
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user