mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
perf dso: Fix heap overflow in dso__get_filename() on decompressed path
dso__get_filename() allocates name with malloc(PATH_MAX), but the
dso__filename_with_chroot() path replaces name with an asprintf'd
exact-size string (e.g. 8 bytes for "/a/b.ko"). When the DSO needs
decompression, dso__decompress_kmodule_path() writes the temp path
("/tmp/perf-kmod-XXXXXX", 22 bytes) into newpath, and strcpy(name,
newpath) overflows the smaller allocation.
Replace the strcpy with strdup(newpath) + free(name) so the buffer
is always correctly sized for its content.
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Fixes: 1d6b3c9ba7 ("perf tools: Decompress kernel module when reading DSO data")
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
This commit is contained in:
parent
063c647b24
commit
f973e52a99
|
|
@ -603,8 +603,15 @@ static char *dso__get_filename(struct dso *dso, const char *root_dir,
|
|||
|
||||
/* empty pathname means file wasn't actually compressed */
|
||||
if (newpath[0] != '\0') {
|
||||
char *tmp = strdup(newpath);
|
||||
|
||||
if (!tmp) {
|
||||
unlink(newpath);
|
||||
goto out;
|
||||
}
|
||||
free(name);
|
||||
name = tmp;
|
||||
*decomp = true;
|
||||
strcpy(name, newpath);
|
||||
}
|
||||
}
|
||||
return name;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user