[PATCH] perf ftrace: Fix leak in parse_filter_event

Michail Tatas <[email protected]> Mon, 3 Aug 2026 10:50:04 +0300
Newsgroups org.kernel.vger.linux-perf-users,org.kernel.vger.linux-kernel
Message-ID <anBILHWZfxku7OWq@michalis-linux>
strsep() advances the pointer given to it. After the loop s is
either NULL (on success) or points mid buffer (early exit if malloc
fails) so the original buffer is never freed properly.
Fix by adding a tmp pointer for use by strsep and free the original
pointer

Signed-off-by: Michail Tatas <[email protected]>
---
 tools/perf/builtin-ftrace.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/tools/perf/builtin-ftrace.c b/tools/perf/builtin-ftrace.c
index f7126196b092..4f881a40c311 100644
--- a/tools/perf/builtin-ftrace.c
+++ b/tools/perf/builtin-ftrace.c
@@ -1607,14 +1607,15 @@ static int parse_filter_event(const struct option *opt, const char *str,
 {
 	struct list_head *head = opt->value;
 	struct filter_entry *entry;
-	char *s, *p;
+	char *s, *p, *tmp;
 	int ret = -ENOMEM;
 
 	s = strdup(str);
 	if (s == NULL)
 		return -ENOMEM;
 
-	while ((p = strsep(&s, ",")) != NULL) {
+	tmp = s;
+	while ((p = strsep(&tmp, ",")) != NULL) {
 		entry = malloc(sizeof(*entry) + strlen(p) + 1);
 		if (entry == NULL)
 			goto out;
-- 
2.43.0