* [PATCH] perf powerpc-vpadtl: Fix off-by-one in auxtrace_info minimum size check
@ 2026-08-24 2:55 Wang Yan
2026-08-24 5:55 ` Adrian Hunter
0 siblings, 1 reply; 2+ messages in thread
From: Wang Yan @ 2026-08-24 2:55 UTC (permalink / raw)
To: peterz, mingo, acme, namhyung
Cc: mark.rutland, alexander.shishkin, jolsa, irogers, adrian.hunter,
james.clark, atrajeev, wangyan01, tanze, linux-perf-users,
linux-kernel, stable
min_sz is set to sizeof(u64) * POWERPC_VPADTL_TYPE, but the code reads
auxtrace_info->priv[POWERPC_VPADTL_TYPE], which needs at least
POWERPC_VPADTL_TYPE + 1 elements. POWERPC_VPADTL_TYPE is the first
enumerator of the priv index enum (0), so min_sz evaluates to 0 and the
check validates only the perf_record_auxtrace_info header itself. A
PERF_RECORD_AUXTRACE_INFO event carrying a zero-length priv array then
passes the size check, and the subsequent priv[POWERPC_VPADTL_TYPE]
read runs one u64 past the validated region.
This is the same off-by-one fixed for Intel PT by commit c4362d5e1a5e
("perf intel-pt: Fix off-by-one in auxtrace_info minimum size check")
and for Intel BTS by commit b9fb8225951c ("perf intel-bts: Fix off-by-one
in auxtrace_info minimum size check").
Use sizeof(u64) * (POWERPC_VPADTL_TYPE + 1) so the highest accessed
priv index is covered by the minimum-size validation.
Fixes: c4bbd4ec2e50 ("perf powerpc: Process auxtrace events and display in 'perf report -D'")
Cc: stable@vger.kernel.org
Signed-off-by: Wang Yan <wangyan01@kylinos.cn>
---
tools/perf/util/powerpc-vpadtl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/perf/util/powerpc-vpadtl.c b/tools/perf/util/powerpc-vpadtl.c
index 710f3093f3f9..c15636eef34b 100644
--- a/tools/perf/util/powerpc-vpadtl.c
+++ b/tools/perf/util/powerpc-vpadtl.c
@@ -683,7 +683,7 @@ int powerpc_vpadtl_process_auxtrace_info(union perf_event *event,
struct perf_session *session)
{
struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
- size_t min_sz = sizeof(u64) * POWERPC_VPADTL_TYPE;
+ size_t min_sz = sizeof(u64) * (POWERPC_VPADTL_TYPE + 1);
struct powerpc_vpadtl *vpa;
int err;
--
2.25.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] perf powerpc-vpadtl: Fix off-by-one in auxtrace_info minimum size check
2026-08-24 2:55 [PATCH] perf powerpc-vpadtl: Fix off-by-one in auxtrace_info minimum size check Wang Yan
@ 2026-08-24 5:55 ` Adrian Hunter
0 siblings, 0 replies; 2+ messages in thread
From: Adrian Hunter @ 2026-08-24 5:55 UTC (permalink / raw)
To: Wang Yan, peterz, mingo, acme, namhyung
Cc: mark.rutland, alexander.shishkin, jolsa, irogers, james.clark,
atrajeev, tanze, linux-perf-users, linux-kernel, stable
On 24/08/2026 05:55, Wang Yan wrote:
> min_sz is set to sizeof(u64) * POWERPC_VPADTL_TYPE, but the code reads
> auxtrace_info->priv[POWERPC_VPADTL_TYPE], which needs at least
> POWERPC_VPADTL_TYPE + 1 elements. POWERPC_VPADTL_TYPE is the first
> enumerator of the priv index enum (0), so min_sz evaluates to 0 and the
> check validates only the perf_record_auxtrace_info header itself. A
> PERF_RECORD_AUXTRACE_INFO event carrying a zero-length priv array then
> passes the size check, and the subsequent priv[POWERPC_VPADTL_TYPE]
> read runs one u64 past the validated region.
>
> This is the same off-by-one fixed for Intel PT by commit c4362d5e1a5e
> ("perf intel-pt: Fix off-by-one in auxtrace_info minimum size check")
> and for Intel BTS by commit b9fb8225951c ("perf intel-bts: Fix off-by-one
> in auxtrace_info minimum size check").
>
> Use sizeof(u64) * (POWERPC_VPADTL_TYPE + 1) so the highest accessed
> priv index is covered by the minimum-size validation.
>
> Fixes: c4bbd4ec2e50 ("perf powerpc: Process auxtrace events and display in 'perf report -D'")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wang Yan <wangyan01@kylinos.cn>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
> ---
> tools/perf/util/powerpc-vpadtl.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tools/perf/util/powerpc-vpadtl.c b/tools/perf/util/powerpc-vpadtl.c
> index 710f3093f3f9..c15636eef34b 100644
> --- a/tools/perf/util/powerpc-vpadtl.c
> +++ b/tools/perf/util/powerpc-vpadtl.c
> @@ -683,7 +683,7 @@ int powerpc_vpadtl_process_auxtrace_info(union perf_event *event,
> struct perf_session *session)
> {
> struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
> - size_t min_sz = sizeof(u64) * POWERPC_VPADTL_TYPE;
> + size_t min_sz = sizeof(u64) * (POWERPC_VPADTL_TYPE + 1);
> struct powerpc_vpadtl *vpa;
> int err;
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-24 7:44 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-24 2:55 [PATCH] perf powerpc-vpadtl: Fix off-by-one in auxtrace_info minimum size check Wang Yan
2026-08-24 5:55 ` Adrian Hunter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®