All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Tanushree Shah" <tshah@linux.ibm.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v3 3/5] perf trace-event: Avoid double free in trace_event__cleanup()
Date: Fri, 24 Jul 2026 14:55:14 +0000	[thread overview]
Message-ID: <20260724145514.90C7E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260724141316.99507-4-tshah@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Calling trace_event__init() repeatedly on the same struct trace_event leaks the previously allocated tep_handle and plugins.
--

--- Patch [3]: [PATCH v3 3/5] perf trace-event: Avoid double free in trace_event__cleanup() ---
commit 1eb2775370e0095c8df022b4a83dcd46f4b90b94
Author: Tanushree Shah <tshah@linux.ibm.com>

perf trace-event: Avoid double free in trace_event__cleanup()

trace_event__cleanup() frees t->pevent but never clears the pointer. It can be
called twice on the same trace_event: once from trace_report()'s error path,
and again from perf_session__delete() during session teardown, resulting in a
double free / use-after-free.

> diff --git a/tools/perf/util/trace-event.c b/tools/perf/util/trace-event.c
> index 6a8c66c64b705..cf40e98d16177 100644
> --- a/tools/perf/util/trace-event.c
> +++ b/tools/perf/util/trace-event.c
> @@ -63,8 +63,12 @@ int trace_event__register_resolver(struct machine *machine,
>  
>  void trace_event__cleanup(struct trace_event *t)
>  {
> +	if (!t->pevent)
> +		return;
> +

[Severity: High]
This isn't a bug introduced by this patch, but while we are making it safe
to call trace_event__cleanup() multiple times, should we also call it from
trace_event__init() to prevent memory leaks?

If a maliciously crafted perf.data file contains multiple
PERF_RECORD_HEADER_TRACING_DATA headers, trace_report() can be called
multiple times on the same session, invoking trace_event__init() repeatedly:

tools/perf/util/trace-event-read.c:trace_report() {
    ...
	if (trace_event__init(tevent)) {
    ...
}

This overwrites the previously allocated tep_handle and plugins without
freeing them, leaking the memory:

tools/perf/util/trace-event.c:trace_event__init() {
    ...
		t->plugin_list = tep_load_plugins(pevent);
		t->pevent  = pevent;
    ...
}

>  	tep_unload_plugins(t->plugin_list, t->pevent);
>  	tep_free(t->pevent);
> +	t->pevent = NULL;
>  }
>  
>  /*

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260724141316.99507-1-tshah@linux.ibm.com?part=3

  reply	other threads:[~2026-07-24 14:55 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-24 14:13 [PATCH v3 0/5] perf trace-event: Fix security bugs in trace-event-read.c and trace-event.c Tanushree Shah
2026-07-24 14:13 ` [PATCH v3 1/5] perf trace-event: Fix buffer overflow in read_string() Tanushree Shah
2026-07-24 14:47   ` sashiko-bot
2026-07-24 14:13 ` [PATCH v3 2/5] perf trace-event: Fix integer truncation in do_read() and skip() Tanushree Shah
2026-07-24 14:47   ` sashiko-bot
2026-07-24 14:13 ` [PATCH v3 3/5] perf trace-event: Avoid double free in trace_event__cleanup() Tanushree Shah
2026-07-24 14:55   ` sashiko-bot [this message]
2026-07-24 14:13 ` [PATCH v3 4/5] perf trace-event: Fix heap buffer overflow in read_ftrace_printk() Tanushree Shah
2026-07-24 14:54   ` sashiko-bot
2026-07-24 14:13 ` [PATCH v3 5/5] perf trace-event: Fix infinite loop in skip() Tanushree Shah
2026-07-24 14:57   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260724145514.90C7E1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tshah@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.