Re: [PATCH] uprobes: Fix NULL pointer dereference in hprobe_expire()
Andrii Nakryiko <[email protected]> Wed, 29 Jul 2026 12:31:08 -0700
| Newsgroups | org.kernel.vger.linux-trace-kernel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-perf-users,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAEf4BzYON57L_HD71qUOdRdni_=1S-Xomz27PeDBxbbXDy0Jug@mail.gmail.com> |
On Wed, Jul 29, 2026 at 9:02 AM Oleg Nesterov <[email protected]> wrote: > > On 07/29, Breno Leitao wrote: > > > > --- a/kernel/events/uprobes.c > > +++ b/kernel/events/uprobes.c > > @@ -832,7 +832,7 @@ static struct uprobe *hprobe_expire(struct hprobe *hprobe, bool get) > > if (try_cmpxchg(&hprobe->state, &hstate, uprobe ? HPROBE_STABLE : HPROBE_GONE)) { > > /* We won the race, we are the ones to unlock SRCU */ > > __srcu_read_unlock(&uretprobes_srcu, hprobe->srcu_idx); > > - return get ? get_uprobe(uprobe) : uprobe; > > + return get && uprobe ? get_uprobe(uprobe) : uprobe; > > Well, looks "obviously correct". At least the current code is obviously > wrong, it even checks uprobe != NULL 3 lines above. > > Andrii ? > Yes, indeed, I'm more surprised this didn't come up much earlier (probably it's rare enough to have uretprobe with refcnt at zero during fork). The fix looks good, thanks! Acked-by: Andrii Nakryiko <[email protected]> > Acked-by: Oleg Nesterov <[email protected]> > >