Re: [PATCH] tracing: Fix NULL pointer dereference in module event cache removal

Steven Rostedt <[email protected]>
Newsgroups org.kernel.vger.linux-trace-kernel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Wed, 12 Aug 2026 01:39:03 +0800
Hui Su <[email protected]> wrote:

> A module-only event filter such as ":mod:foo" is cached with a NULL
> event_mod->match when foo has not been loaded. If a later write tries to
> remove a specific match from the same module, remove_cache_mod() passes
> the NULL cached match to strcmp(), causing a NULL pointer dereference.
> 
> The issue can be reproduced from userspace by keeping one set_event file
> descriptor open across both writes:
> 
>   mount -t tracefs tracefs /sys/kernel/tracing
>   exec 3>/sys/kernel/tracing/set_event
>   printf ':mod:trace_events_kunit_missing\n' >&3
>   printf '!foo_bar:mod:trace_events_kunit_missing\n' >&3
> 
> The descriptor must remain open because reopening set_event with O_TRUNC
> calls ftrace_clear_events() and removes the cached module filter before
> the second write.
> 
> The crash was reproduced on x86_64 QEMU while KUnit workers contended on
> the event tracing path:
> 
>   BUG: kernel NULL pointer dereference, address: 0000000000000000
>   #PF: supervisor read access in kernel mode
>   RIP: 0010:strcmp+0x10/0x30
>   Call Trace:
>    __ftrace_set_clr_event_nolock+0x373/0x4a0
>    ftrace_set_clr_event+0xf0/0x180
>    ftrace_event_write+0xdf/0x110
>    vfs_write+0xf6/0x440
>    ksys_write+0x68/0xe0
>    do_syscall_64+0xf9/0x540
>    entry_SYSCALL_64_after_hwframe+0x77/0x7f
> 
> Check event_mod->match before comparing it, consistent with the existing
> NULL checks for the cached system and event fields. The mismatched removal
> continues to return -EINVAL; a broad cached module filter is removed with
> "!:mod:<module>".

Thanks but it's actually easier to trigger it this way:

  echo ':mod:trace_events_kunit_missing' > /sys/kernel/tracing/set_event
  echo '!foo_bar:mod:trace_events_kunit_missing' >> /sys/kernel/tracing/set_event

as '>>' doesn't truncate.

I'll queue it up and start testing it.

-- Steve


> 
> Fixes: b355247df104 ("tracing: Cache \":mod:\" events for modules not loaded yet")
> Reported-by: [email protected]
> Closes: https://lore.kernel.org/lkml/[email protected]/
> Signed-off-by: Hui Su <[email protected]>
> ---
>  kernel/trace/trace_events.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/kernel/trace/trace_events.c b/kernel/trace/trace_events.c
> index c01b10b99f67..032f741ba616 100644
> --- a/kernel/trace/trace_events.c
> +++ b/kernel/trace/trace_events.c
> @@ -945,7 +945,7 @@ static int remove_cache_mod(struct trace_array *tr, const char *mod,
>  		if (strcmp(event_mod->module, mod) != 0)
>  			continue;
>  
> -		if (match && strcmp(event_mod->match, match) != 0)
> +		if (match && (!event_mod->match || strcmp(event_mod->match, match) != 0))
>  			continue;
>  
>  		if (system &&
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.