linux/kernel/trace
Donggeun Yoo a5e70ba87c tracing: Fix memory corruption from the histogram stacktrace modifier
parse_field() sets HIST_FIELD_FL_STACKTRACE from the ".stacktrace"
modifier before it looks the field name up, and nothing afterwards
checks that the name resolved to a field which holds a stacktrace.
create_hist_field() picks HIST_FIELD_FN_STACK on the strength of the
field pointer alone, which reads a __data_loc word from the record and
follows its low 16 bits as an offset into the same record.
event_hist_trigger() takes the first word there as an entry count and
copies that many longs into a 31 entry array:

	n_entries = *stack;
	memcpy(entries, ++stack, n_entries * sizeof(unsigned long));

Neither end of that copy is bounded, and the count is whatever the event
holds at the offset, so any field will do:

  # cd /sys/kernel/tracing/events/sched/sched_process_fork
  # echo 'hist:keys=parent_pid.stacktrace' > trigger
  # (true)

  BUG: kernel NULL pointer dereference, address: 0000000000000008
  RIP: 0010:rb_insert_color+0x18/0x130
   timerqueue_linked_add+0x7e/0xd0
   enqueue_hrtimer+0x39/0xb0
   __hrtimer_run_queues+0x10f/0x1f0
   </IRQ>
  RIP: 0010:memcpy+0xc/0x30
   event_hist_trigger+0x165/0x690

The timer interrupt landed on the rbtree the copy had already run over.
No debug options are needed for this; KASAN reports the same write as an
out-of-bounds read of 13835058055416381440 bytes.

Documentation/trace/histogram.rst already states the rule, "must be a
long[] type", so enforce it once the name has been resolved. Names which
resolve to no field at all, "hitcount.stacktrace" and the common_*
pseudo-fields, are refused for the same reason: they hold no stacktrace
to read.

Cc: stable@vger.kernel.org
Fixes: cc5fc8bfc9 ("tracing/histogram: Add stacktrace type")
Link: https://patch.msgid.link/20260907155045.692664-2-donggeunyoo.kernel@gmail.com
Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
2026-09-11 14:01:16 -04:00
..
rv rv: Fix 32-bit build of nomiss KUnit test 2026-08-04 16:11:27 +02:00
blktrace.c block-7.0-20260305 2026-03-06 08:36:18 -08:00
bpf_trace.c bpf: Make bpf_trampoline_multi_detach return void 2026-08-13 02:52:23 +02:00
bpf_trace.h tracing/treewide: Remove second parameter of __assign_str() 2024-05-22 20:14:47 -04:00
error_report-traces.c
fgraph.c fgraph: Remove unused FGRAPH_MAX_INDEX 2026-09-11 13:37:50 -04:00
fprobe.c treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
ftrace_internal.h function_graph: Make fgraph_update_pid_func() a stub for !DYNAMIC_FTRACE 2024-06-10 18:08:23 -04:00
ftrace.c ftrace: Synchronize the initialization of ftrace_ops 2026-09-02 11:08:21 -04:00
Kconfig tracing/probes: Support dumping fetcharg program for debugging dynamic events 2026-07-02 21:12:40 +09:00
kprobe_event_gen_test.c tracing: Fix wrong return in kprobe_event_gen_test.c 2023-03-19 12:20:48 -04:00
Makefile tracing: Updates for v7.2: 2026-06-18 20:53:00 -07:00
pid_list.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
pid_list.h trace/pid_list: optimize pid_list->lock contention 2025-11-13 15:15:54 -05:00
power-traces.c PM: cpufreq: powernv/tracing: Move powernv_throttle trace event 2025-07-21 16:40:56 -04:00
preemptirq_delay_test.c tracing: Reject invalid preemptirq_delay_test CPU affinity 2026-07-28 07:18:50 -04:00
remote_test_events.h tracing: Add a trace remote module for testing 2026-03-09 12:33:55 -04:00
remote_test.c tracing: Fix desc in error path for the trace remote test module 2026-05-16 16:11:04 -04:00
rethook.c tracing: Fix typo "availabe" in comment 2026-09-11 13:54:14 -04:00
ring_buffer_benchmark.c tracing: Fix subbuf resize races with trace_pipe_raw readers 2026-09-04 16:19:07 -04:00
ring_buffer.c tracing fixes for v7.3: 2026-09-06 14:21:24 -07:00
rpm-traces.c
simple_ring_buffer.c tracing: Fix retry exhaustion in simple ring buffer reader swap 2026-08-27 21:31:41 -04:00
synth_event_gen_test.c tracing / synthetic: Disable events after testing in synth_event_gen_test_init() 2023-12-21 10:04:45 -05:00
trace_benchmark.c tracing: Improve benchmark test performance by using do_div() 2024-05-13 20:00:57 -04:00
trace_benchmark.h tracing: Add numeric delta time to the trace event benchmark 2022-09-26 13:01:09 -04:00
trace_boot.c tracing/boot: Add support for eprobe, fprobe, and tprobe events 2026-08-08 21:20:55 +09:00
trace_branch.c tracing/branch: Use pr_warn() instead of printk(KERN_WARNING) 2026-05-21 18:03:08 -04:00
trace_btf.c tracing/probes: Fix BTF kflag check for anonymous struct member access 2026-09-03 09:04:25 +09:00
trace_btf.h tracing/probes: Fix BTF kflag check for anonymous struct member access 2026-09-03 09:04:25 +09:00
trace_clock.c tracing: Use atomic64_inc_return() in trace_clock_counter() 2024-10-09 19:59:49 -04:00
trace_dynevent.c tracing/boot: Add support for eprobe, fprobe, and tprobe events 2026-08-08 21:20:55 +09:00
trace_dynevent.h tracing: probes: Fix a possible race in trace_probe_log APIs 2025-05-13 22:23:34 +09:00
trace_entries.h tracing: Fix ftrace event field alignments 2026-02-05 09:47:11 -05:00
trace_eprobe.c treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
trace_event_perf.c perf/ftrace: Fix WARNING in __unregister_ftrace_function 2026-05-29 11:27:40 -04:00
trace_events_filter_test.h
trace_events_filter.c tracing/filters: Fix false positive match in regex_match_full() 2026-07-29 14:32:11 -04:00
trace_events_hist.c tracing: Fix memory corruption from the histogram stacktrace modifier 2026-09-11 14:01:16 -04:00
trace_events_inject.c tracing: Have format file honor EVENT_FILE_FL_FREED 2024-08-07 18:12:46 -04:00
trace_events_synth.c tracing/synthetic: Free type string on error path 2026-07-07 13:59:55 -04:00
trace_events_trigger.c tracing: Cleanup event_enable_trigger_parse() by using __free() 2026-08-11 10:23:38 -04:00
trace_events_user.c tracing/user_events: Don't destroy fields when event removal fails 2026-09-11 13:30:15 -04:00
trace_events.c tracing: Have show_event_filters/triggers files take trace array ref 2026-09-01 16:36:52 -04:00
trace_export.c tracing: Fix ftrace event field alignments 2026-02-05 09:47:11 -05:00
trace_fprobe.c Probes updates for v7.3: 2026-08-20 15:11:52 -07:00
trace_functions_graph.c function_graph: Use the saved entry's size when reprinting it 2026-09-11 13:39:08 -04:00
trace_functions.c ftrace: Take trace_array reference before accessing its ftrace_ops 2026-09-01 16:38:19 -04:00
trace_hwlat.c tracing: Fix false sharing in hwlat get_sample() 2026-02-10 03:36:39 -05:00
trace_irqsoff.c tracing: Allow tracer to add more than 32 options 2025-11-04 21:44:00 +09:00
trace_kdb.c tracing: Allow tracer to add more than 32 options 2025-11-04 21:44:00 +09:00
trace_kprobe_selftest.c tracing: arm64: Avoid missing-prototype warnings 2023-07-12 12:06:04 -04:00
trace_kprobe_selftest.h
trace_kprobe.c tracing/probes: Treating longer symbol name on event comparation 2026-07-28 23:55:35 +09:00
trace_mmiotrace.c tracing updates for v7.3: 2026-08-19 14:06:14 -07:00
trace_nop.c
trace_osnoise.c tracing/osnoise: Call synchronize_rcu() when unregistering 2026-07-06 14:56:18 -04:00
trace_output.c tracing updates for v7.1: 2026-04-17 09:43:12 -07:00
trace_output.h tracing: Allow tracer to add more than 32 options 2025-11-04 21:44:00 +09:00
trace_pid.c tracing: Move pid filtering into trace_pid.c 2026-02-08 21:01:13 -05:00
trace_preemptirq.c tracing: Add a no-rcu-check version of trace_##event##_enabled() 2026-07-07 10:42:29 -04:00
trace_printk.c kernel/trace/trace_printk: Use kstrdup() instead of kmalloc() and strcpy() 2026-07-28 07:18:48 -04:00
trace_probe_kernel.h tracing/probes: Fix extra whitespace in trace_probe_kernel.h 2026-07-21 18:00:13 +09:00
trace_probe_tmpl.h tracing/probes: Add this_cpu_read() and this_cpu_ptr() dereference method to fetcharg 2026-07-14 22:43:16 +09:00
trace_probe.c tracing/probes: Fix use-after-free on field name/type of events with multiple probes 2026-09-03 09:04:25 +09:00
trace_probe.h tracing/probes: Fix use-after-free on field name/type of events with multiple probes 2026-09-03 09:04:25 +09:00
trace_recursion_record.c tracing: Switch trace_recursion_record.c code over to use guard() 2026-05-21 18:03:07 -04:00
trace_remote.c treewide: refresh kmalloc_obj() conversions 2026-09-04 21:37:00 -07:00
trace_sched_switch.c tracing: Use strscpy() instead of strcpy() in trace_sched_switch 2026-07-28 07:18:50 -04:00
trace_sched_wakeup.c tracing: Allow tracer to add more than 32 options 2025-11-04 21:44:00 +09:00
trace_selftest_dynamic.c
trace_selftest.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
trace_seq.c tracing: Add bitmask-list option for human-readable bitmask display 2026-01-26 17:00:50 -05:00
trace_snapshot.c tracing: Remove duplicate latency_fsnotify() stub 2026-03-31 14:58:39 -04:00
trace_stack.c ftrace: Take trace_array reference before accessing its ftrace_ops 2026-09-01 16:38:19 -04:00
trace_stat.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
trace_stat.h
trace_synth.h tracing: Allow synthetic events to pass around stacktraces 2023-01-25 10:31:24 -05:00
trace_syscalls.c tracing: Make per-template BTF id lists file-local 2026-08-05 22:02:29 -04:00
trace_uprobe.c uprobes: guard trace cleanup against error pointers 2026-09-01 09:50:11 +09:00
trace.c tracing: Fix comment in tracing_buffers_splice_read() 2026-09-04 16:19:29 -04:00
trace.h tracing: Fix subbuf resize races with trace_pipe_raw readers 2026-09-04 16:19:07 -04:00
tracing_map.c tracing: Simplify pages allocation for tracing_map logic 2026-05-21 18:12:10 -04:00
tracing_map.h tracing: Simplify pages allocation for tracing_map logic 2026-05-21 18:12:10 -04:00
undefsyms_base.c tracing: Make undefsyms_base.c a first-class citizen 2026-04-22 11:24:41 -04:00