linux/tools/lib
Naveed Khan 77f02c9926 libbpf: Fix double-free of distilled base BTF on .BTF.ext parse error
When btf_parse_elf() is called without a caller-supplied base_btf (i.e.
via the public btf__parse_elf()) and the object file carries a .BTF.base
(distilled base) section, a dist_base_btf object is created and used as
the base of the split BTF built from the .BTF section.  Because base_btf
is NULL, the relocation block that would otherwise free and clear
dist_base_btf is skipped, and ownership of dist_base_btf is instead
transferred to the split btf by setting btf->owns_base = true.

That ownership transfer was performed before the fallible btf_ext__new()
call that parses the .BTF.ext section.  If .BTF.ext is malformed,
btf_ext__new() fails and the function jumps to the error path, which
frees dist_base_btf directly and then frees btf.  Since owns_base is
already set, btf__free(btf) also frees btf->base_btf, which is the same
dist_base_btf object.  The result is a use-after-free read followed by a
double free of the base BTF, driven entirely by a crafted object file
(a .BTF + .BTF.base + malformed .BTF.ext combination) passed to
btf__parse_elf(), as used by bpftool, pahole and similar tools.

Transfer ownership only after .BTF.ext has been parsed successfully, so
that any earlier failure leaves dist_base_btf owned solely by the local
cleanup path and it is freed exactly once.

Signed-off-by: Naveed Khan <naveed@digiscrypt.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/178345549172.94179.7948304165383170781@digiscrypt.com
2026-07-10 14:53:29 -07:00
..
api tools lib api: Fix mount_overload() snprintf truncation and toupper range 2026-06-10 18:56:02 -03:00
bpf libbpf: Fix double-free of distilled base BTF on .BTF.ext parse error 2026-07-10 14:53:29 -07:00
perf libperf: Document code simplification case for widening struct perf_cpu 2026-06-10 15:23:54 -03:00
python kdoc: xforms: ignore special static/inline macros 2026-06-23 14:41:52 -06:00
subcmd perf tools changes for v7.2: 2026-06-23 11:34:49 -07:00
symbol perf: Fix off-by-one stack buffer overflow in kallsyms__parse() 2026-06-04 10:58:47 -03:00
thermal tools: lib: thermal: Correct CFLAGS and LDFLAGS in pkg-config template 2026-01-20 20:37:38 +01:00
argv_split.c tools lib: Move argv_{split,free} from tools/perf/util/ 2019-07-01 22:50:40 -03:00
bitmap.c mm/vma: add vma_flags_empty(), vma_flags_and(), vma_flags_diff_pair() 2026-04-05 13:53:38 -07:00
cmdline.c memblock test: fix implicit declaration of function 'memparse' 2024-08-06 08:21:25 +03:00
ctype.c tools perf: Move from sane_ctype.h obtained from git to the Linux's original 2019-06-25 21:02:47 -03:00
find_bit.c tools: sync find_bit() implementation 2022-09-21 12:21:44 -07:00
hweight.c
list_sort.c tools/lib/list_sort: remove unnecessary header includes 2024-11-05 17:12:33 -08:00
rbtree.c tools lib rbtree: pick some improvements from the kernel rbtree code 2024-05-08 08:41:27 -07:00
slab.c lib/rbtree: enable userland test suite for rbtree related data structure 2025-03-17 12:17:00 -07:00
str_error_r.c
string.c perf annotate: Add disasm_line__parse() to parse raw instruction for powerpc 2024-07-31 16:12:59 -03:00
vsprintf.c
zalloc.c tools lib: Adopt zalloc()/zfree() from tools/perf 2019-07-09 10:13:26 -03:00