All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Arnaldo Carvalho de Melo" <acme@kernel.org>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH 1/5] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy
Date: Mon, 27 Jul 2026 16:32:57 +0000	[thread overview]
Message-ID: <20260727163257.AC7821F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260727161705.64807-2-acme@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Medium] Missing NULL pointer checks for `ts->br_stack_rb` cause deterministic crashes when processing events on a thread stack that lacks an allocated branch stack.
--

--- Patch [1]: [PATCH 1/5] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy ---
commit 15a96772c52a6e753408d6e7f8ded1a5bb10c331
Author: Arnaldo Carvalho de Melo <acme@redhat.com>

perf thread-stack: Fix heap buffer overflow on branch stack wrap copy

This commit fixes a heap buffer overflow in thread_stack__br_sample() where
the memcpy size for the wrap-around portion used an unbounded ts->br_stack_pos
instead of the bounded nr variable.

> diff --git a/tools/perf/util/thread-stack.c b/tools/perf/util/thread-stack.c
> index c5ce741b07446..1360f44421ef8 100644
> --- a/tools/perf/util/thread-stack.c
> +++ b/tools/perf/util/thread-stack.c
> @@ -642,7 +642,7 @@ void thread_stack__br_sample(struct thread *thread, int cpu,
>  		sz -= nr;
>  		be = &dst->entries[nr];
>  		nr = min(ts->br_stack_pos, sz);
> -		memcpy(be, &src->entries[0], bsz * ts->br_stack_pos);
> +		memcpy(be, &src->entries[0], bsz * nr);
>  	}
>  }

[Severity: Medium]
This is a pre-existing issue, but while looking at thread_stack__br_sample(),
is there a missing NULL pointer check for ts->br_stack_rb?

Earlier in this function, the code does:

	src = ts->br_stack_rb;
	if (!src->nr)
		return;

If thread_stack__process() supersedes an existing thread stack and allocates a
new one with a 0 branch stack size, or if the allocation for ts->br_stack_rb
fails during thread_stack__init(), ts->br_stack_rb can be NULL.

When thread_stack__br_sample() or thread_stack__update_br_stack() is
subsequently called, will this unconditionally dereference the NULL pointer
and cause the perf tool to crash?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260727161705.64807-1-acme@kernel.org?part=1

  reply	other threads:[~2026-07-27 16:32 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 16:17 [PATCHES 0/5 v1] perf tools auxtrace hardening series Arnaldo Carvalho de Melo
2026-07-27 16:17 ` [PATCH 1/5] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy Arnaldo Carvalho de Melo
2026-07-27 16:32   ` sashiko-bot [this message]
2026-07-27 16:17 ` [PATCH 2/5] perf auxtrace: Fix queue grow overflow and old array leak Arnaldo Carvalho de Melo
2026-07-27 16:29   ` sashiko-bot
2026-07-27 16:17 ` [PATCH 3/5] perf intel-pt: Fix off-by-one in auxtrace_info minimum size check Arnaldo Carvalho de Melo
2026-07-27 16:35   ` sashiko-bot
2026-07-27 16:17 ` [PATCH 4/5] perf intel-bts: " Arnaldo Carvalho de Melo
2026-07-27 16:34   ` sashiko-bot
2026-07-27 16:17 ` [PATCH 5/5] perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero Arnaldo Carvalho de Melo
2026-07-27 16:32   ` sashiko-bot
2026-07-27 16:31 ` [PATCHES 0/5 v1] perf tools auxtrace hardening series James Clark

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727163257.AC7821F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=acme@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.