mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()
If trace_probe_log.argc is 0 in __trace_probe_log_err(), the loop
constructing the command string will not execute and p will remain equal to
command. Writing to *(p - 1) will cause an out-of-bounds access before
command. This should not happen, but better to be treated.
Reject if trace_probe_log.argc is 0.
Link: https://lore.kernel.org/all/178454233992.290363.18323091580600697731.stgit@devnote2/
Fixes: ab105a4fb8 ("tracing: Use tracing error_log with probe events")
Cc: stable@vger.kernel.org
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
This commit is contained in:
parent
15f197856d
commit
a9d6fb2840
|
|
@ -188,7 +188,7 @@ void __trace_probe_log_err(int offset, int err_type)
|
|||
|
||||
lockdep_assert_held(&dyn_event_ops_mutex);
|
||||
|
||||
if (!trace_probe_log.argv)
|
||||
if (!trace_probe_log.argv || !trace_probe_log.argc)
|
||||
return;
|
||||
|
||||
/* Recalculate the length and allocate buffer */
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user