Re: [PATCH 11/12] perf jitdump: Validate sym string NUL-termination in code load
Ian Rogers <[email protected]> Wed, 5 Aug 2026 12:19:40 -0700
| Newsgroups | org.kernel.vger.linux-perf-users,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAP-5=fUdodt6KrnKqPs0NYwp3tUDQMfQ9OHDYKGPsW=U-MhHLw@mail.gmail.com> |
On Wed, Aug 5, 2026 at 6:32 AM Arnaldo Carvalho de Melo <[email protected]> wrote: > > From: Arnaldo Carvalho de Melo <[email protected]> > > jit_repipe_code_load() computes sym = (void *)jr + sizeof(jr->load) and > passes it to jit_emit_elf() which calls strlen(sym) via jit_write_elf(). > If code_size equals total_size - sizeof(jr->load), the sym pointer > aliases the code blob with no NUL terminator, and strlen() scans past > the buffer into adjacent heap memory. > > Add a memchr() check to verify the symbol name is NUL-terminated within > the region between the load header and the code blob before use. > > Fixes: 598b7c6919c7bbcc ("perf jit: add source line info support") > Reported-by: sashiko-bot <[email protected]> > Cc: Stephane Eranian <[email protected]> > Assisted-by: Claude:claude-opus-4.6 > Signed-off-by: Arnaldo Carvalho de Melo <[email protected]> Reviewed-by: Ian Rogers <[email protected]> Thanks! Ian > --- > tools/perf/util/jitdump.c | 7 +++++++ > 1 file changed, 7 insertions(+) > > diff --git a/tools/perf/util/jitdump.c b/tools/perf/util/jitdump.c > index 87612ef3e232598e..5f3a53f818c29f58 100644 > --- a/tools/perf/util/jitdump.c > +++ b/tools/perf/util/jitdump.c > @@ -487,6 +487,13 @@ static int jit_repipe_code_load(struct jit_buf_desc *jd, union jr_entry *jr) > > sym = (void *)((unsigned long)jr + sizeof(jr->load)); > code = (unsigned long)jr + jr->load.p.total_size - csize; > + > + /* sym string lives between the load header and the code blob */ > + if (!memchr(sym, '\0', code - (unsigned long)sym)) { > + pr_warning("jitdump: unterminated symbol name in code_load record\n"); > + return -1; > + } > + > count = jr->load.code_index; > idr_size = jd->machine->id_hdr_size; > > -- > 2.55.0 >