From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1EF4A1E5B63 for ; Sun, 21 Jun 2026 19:23:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782069809; cv=none; b=oDS+W8U7KKxXU3Sk44+Mt3x1ty9ulYkCbd2dDAmvKNkEJGvmtWr3FjMLGk6oxGrcAdYbxM3/TtCJsxMc1aq2bDpAIWWkhHHLMlAXOgAXf8+y3y+fhEYPJkdDPKIfMAjCtb2oMSw6kiSoLCQVf7hqUh0RwmySnTGblwsIiWnBORE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782069809; c=relaxed/simple; bh=uA04HhTsQ8dsNxyfMLdub768NjxZBn1yPSaIJCrMcAk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dz5OIzIJoah32EIIsEF8JUUvJqtdwItWyITWXXY2dlUcw1FdQXQzXb4JiOYCKiE72ynXTwEPaEQaIvRHSvHVRXbyYINOn+cHWd9wY8+HuYBP6Cz72gsPajy5CGHkoZNtYPklhKsFiX+UQHxYq4+SpBZ4HA1bEIwZh55eQUhHYb8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XJv7qvYz; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XJv7qvYz" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-490b8ac62baso41800205e9.0 for ; Sun, 21 Jun 2026 12:23:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782069806; x=1782674606; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=be9MjW25f2njwerBgXRPJ/M+aGJqyGySllhx7C6vl6k=; b=XJv7qvYz6E2DTU5WEROSjG1ev5A803giayoMq/Huhaak+H95LS+snqA6HtYCmOrSNb AGBOGw56OYtF0Itppy1liNkJGFOQczdvJemgOnWwkXSB1iJeIu+vh0e5WlYo/Z0WRldO 48PjIm8M0nkc/5i0S41vqLdRULYOHOOT3Lw6V2BfnIzE8H3foGYlQlEcjMWrxfMs6LXq V/2xx4g/6eHkxrbYwspIkTfVfmsBEHKGOnoldf/bARpmxH9F0Ccok9aDxHrlGaBpf+8x bnAHhh3jOqD/651YXAH8flOcqWhy5JZXZ/fGYwMq5PmkQrftaX/f/z+bPIOH1qZFS6uB VIOw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782069806; x=1782674606; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=be9MjW25f2njwerBgXRPJ/M+aGJqyGySllhx7C6vl6k=; b=MT9n2IkHa9T9M0rwCnVMPNoDWPYiVQBE/RYm1pZ4zLZfxOsV3ctTcTRF06Z/IEd67t 13FmMTOVkit/pvPuwC73IBDgB3IvwuUtfgNJApHFEAEZ2F1heF213C7tao/JhxszMeSm OtNKPcPIFBJbROW6WSIush48DhEuwXZ5uNx0CHo94MkkQ85QLdPrHmCWbopKh+givRYd CYLRKfMEAYl6IBDVwW5cSccLnfq+bx3T6E6CzF/W2P6bnYM2ui3Z7B+B2LVmiwqcLI6A UlYufHGDHNLac89FN7uQSNJ7vEJEP6pScqV7J+5U5Goy4s4CRYA8E2Fbpi+eMN1TVlTu Zk1w== X-Forwarded-Encrypted: i=1; AFNElJ83nZ/PPyJgfD7w2qjLS61tlWU17vIDGi75e7G6llAt3l0+fN/WIEH2fP/TNBvVL6kp3JjuccvvYrD+d14=@vger.kernel.org X-Gm-Message-State: AOJu0Yx6wkdNkGt6EB+S5+Xq1w/5LcJ0H42DfQ/PF+M5scM+XvP7kD65 lL8kz5xQX7WoUEvPf54AsrhmUzhSMreTg0xuZ8100Lz1KITADuNzDz/FnZ48 X-Gm-Gg: AfdE7cmh6zJVxxaXqum5vFjUsdA/x49tVFyRa+SX4JV6KBViIpRR9QA4oNQpWZCymcM toa/pJJV81GCPpvGdXYbCDWV8/zlbNBSUoh9dvkUFiEnrVbTM3BYOXpDZekPQDcStJCI9I6P8WC VD5426NOUyYB8GY8WLVslu5TkbM9/JoxwxU7WSnSD8bkxBuMEDE59D+eYNui+T+myx2N+h8UjYs nzCCuws1lSq/Fc1B2SA6Lbm3z2Jpkh9DWdwOIsfTJrhbpruH6GJVaJJk/g8nz2WkhkmJnFdWxfX t9rvGM9Ab9zAdiT09SljOQx1YLfXuupUcoNosGQ1RKV6c3vJUqPTAqV/bMSkIm0sozmmNlkDF6j dumDn83m3unr0nhr+EMgESApwcALT/XRMyZCembv8neIP35bVSIldL27wsw== X-Received: by 2002:a05:600c:6a06:b0:490:b0bf:7606 with SMTP id 5b1f17b1804b1-49240a5bfafmr115465675e9.16.1782069806451; Sun, 21 Jun 2026 12:23:26 -0700 (PDT) Received: from debian.. ([2001:41d0:303:db6b::]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-466643f4e3esm18569656f8f.8.2026.06.21.12.23.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 21 Jun 2026 12:23:25 -0700 (PDT) From: Tristan Madani To: Andrew Morton Cc: Ingo Molnar , Dave Hansen , Tetsuo Handa , linux-kernel@vger.kernel.org, stable@vger.kernel.org, Tristan Madani Subject: [PATCH] profiling: prevent stale prof_cpu_mask access on init failure Date: Sun, 21 Jun 2026 19:23:24 +0000 Message-ID: <20260621192324.2062795-1-tristmd@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Tristan Madani When profiling is enabled at runtime via /sys/kernel/profiling, profile_setup() sets prof_on and profile_init() allocates prof_cpu_mask and attempts to allocate prof_buffer. If all prof_buffer allocations fail, the error path frees prof_cpu_mask but leaves prof_on set. Since profile_tick() runs from timer interrupt context and checks cpumask_available(prof_cpu_mask) without first checking prof_on, it can dereference the freed cpumask between the free and the next reboot. Clear prof_on before freeing prof_cpu_mask so the profiling state remains consistent on allocation failure. Also gate the cpumask access in profile_tick() on prof_on to prevent accessing stale state during the teardown window. Fixes: 22b8ce94708f ("profiling: dynamically enable readprofile at runtime") Cc: stable@vger.kernel.org Signed-off-by: Tristan Madani --- kernel/profile.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/kernel/profile.c b/kernel/profile.c index 984f819b701c9..a166ad9512714 100644 --- a/kernel/profile.c +++ b/kernel/profile.c @@ -123,6 +123,7 @@ int __ref profile_init(void) if (prof_buffer) return 0; + prof_on = 0; free_cpumask_var(prof_cpu_mask); return -ENOMEM; } @@ -325,7 +326,7 @@ void profile_tick(int type) { struct pt_regs *regs = get_irq_regs(); - if (!user_mode(regs) && cpumask_available(prof_cpu_mask) && + if (!user_mode(regs) && prof_on && cpumask_available(prof_cpu_mask) && cpumask_test_cpu(smp_processor_id(), prof_cpu_mask)) profile_hit(type, (void *)profile_pc(regs)); } -- 2.47.3