* [PATCH] kconfig: fix use-after-free when a variable refers to itself
@ 2026-10-05 20:24 lzhan011
0 siblings, 0 replies; only message in thread
From: lzhan011 @ 2026-10-05 20:24 UTC (permalink / raw)
To: nathan, nsc; +Cc: linux-kbuild, linux-kernel
From: lzhan011 <zhangleizhen645@gmail.com>
For a simply expanded variable, variable_add() frees the old value of an
existing variable (or allocates a new variable with an uninitialized
value) before expanding the right-hand side. If the right-hand side
refers to the variable itself, which is a common idiom in Makefiles,
e.g.
X := 1
X := $(X) 2
the expansion reads the freed (or uninitialized) value. With ASan this
is reported as a heap-use-after-free, or a SEGV if X was undefined.
Without ASan, X silently ends up as " 2" instead of "1 2".
Expand the right-hand side before updating the variable, initialize the
value of a newly created variable, and only free the old value when it
is actually replaced. Add a test case for this.
Found by fuzzing Kconfig input with ASan/UBSan.
Fixes: 1175c02506ff ("kconfig: support simply expanded variable")
Assisted-by: Claude:claude-opus-5-5 ASan UBSan libFuzzer
Signed-off-by: lzhan011 <zhangleizhen645@gmail.com>
---
scripts/kconfig/preprocess.c | 21 ++++++++++++-------
.../kconfig/tests/preprocess/variable/Kconfig | 5 +++++
.../tests/preprocess/variable/expected_stderr | 1 +
3 files changed, 20 insertions(+), 7 deletions(-)
diff --git a/scripts/kconfig/preprocess.c b/scripts/kconfig/preprocess.c
index 783abcaa5..db226898c 100644
--- a/scripts/kconfig/preprocess.c
+++ b/scripts/kconfig/preprocess.c
@@ -293,27 +293,33 @@ void variable_add(const char *name, const char *value,
if (flavor == VAR_APPEND) {
flavor = v->flavor;
append = true;
- } else {
- free(v->value);
}
} else {
/* For undefined variables, += assumes the recursive flavor */
if (flavor == VAR_APPEND)
flavor = VAR_RECURSIVE;
+ }
+ /*
+ * Expand the value before touching the variable because the
+ * right-hand side may refer to the variable itself, like
+ * "X := $(X) foo".
+ */
+ if (flavor == VAR_SIMPLE)
+ new_value = expand_string(value);
+ else
+ new_value = xstrdup(value);
+
+ if (!v) {
v = xmalloc(sizeof(*v));
v->name = xstrdup(name);
+ v->value = NULL;
v->exp_count = 0;
list_add_tail(&v->node, &variable_list);
}
v->flavor = flavor;
- if (flavor == VAR_SIMPLE)
- new_value = expand_string(value);
- else
- new_value = xstrdup(value);
-
if (append) {
v->value = xrealloc(v->value,
strlen(v->value) + strlen(new_value) + 2);
@@ -321,6 +327,7 @@ void variable_add(const char *name, const char *value,
strcat(v->value, new_value);
free(new_value);
} else {
+ free(v->value);
v->value = new_value;
}
}
diff --git a/scripts/kconfig/tests/preprocess/variable/Kconfig b/scripts/kconfig/tests/preprocess/variable/Kconfig
index 9ce2f95cb..226114e86 100644
--- a/scripts/kconfig/tests/preprocess/variable/Kconfig
+++ b/scripts/kconfig/tests/preprocess/variable/Kconfig
@@ -51,3 +51,8 @@ $(warning,$(greeting,Hello))
# Unreferenced parameters are just ignored.
$(warning,$(greeting,Hello,John,ignored,ignored))
+
+# Simply expanded variable referring to itself.
+X := 1
+X := $(X) 2
+$(warning,X = $(X))
diff --git a/scripts/kconfig/tests/preprocess/variable/expected_stderr b/scripts/kconfig/tests/preprocess/variable/expected_stderr
index a4841c3fd..7008e3b17 100644
--- a/scripts/kconfig/tests/preprocess/variable/expected_stderr
+++ b/scripts/kconfig/tests/preprocess/variable/expected_stderr
@@ -7,3 +7,4 @@ Kconfig:41: AB = 5
Kconfig:45: Hello, my name is John.
Kconfig:50: Hello, my name is .
Kconfig:53: Hello, my name is John.
+Kconfig:58: X = 1 2
--
2.34.1
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-05 20:24 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 20:24 [PATCH] kconfig: fix use-after-free when a variable refers to itself lzhan011
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®