All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mark Amirkan" <markdamirkan@gmail.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH] perf evsel: Validate branch stack before byte swapping
Date: Thu, 03 Sep 2026 10:21:38 +0000	[thread overview]
Message-ID: <20260903102138.A3B191F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903-sympwn-linux-002-final-v2-v1-1-7c6e4166b814@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] Out-of-bounds memory read and write in PERF_SAMPLE_RAW parsing due to mem_bswap_64 executing before OVERFLOW_CHECK.
--

commit ecce0770a0ee5a1e1d8c053f5ba923c05679efc1
Author: Mark Amirkan <markdamirkan@gmail.com>

perf evsel: Validate branch stack before byte swapping

This commit fixes an out-of-bounds read/write in __evsel__parse_sample()
when handling opposite-endian branch stacks. It moves the overflow check
before the byte-swap loop to prevent truncated samples from causing memory
corruption.

> diff --git a/tools/perf/util/evsel.c b/tools/perf/util/evsel.c
> index d4cb455f4a7d4..cc0bc08577540 100644
> --- a/tools/perf/util/evsel.c
> +++ b/tools/perf/util/evsel.c
[ ... ]
> @@ -3639,6 +3639,8 @@ int __evsel__parse_sample(struct evsel *evsel, union perf_event *event,
>  			e = (struct branch_entry *)&data->branch_stack->hw_idx;
>  		}
>  
> +		OVERFLOW_CHECK(array, sz, max_size);
> +

[Severity: Critical]
This isn't a bug introduced by this patch, but while you are fixing the
byte-swapping bounds check for PERF_SAMPLE_BRANCH_STACK, does the exact
same vulnerability exist just above this code for PERF_SAMPLE_RAW?

In tools/perf/util/evsel.c:__evsel__parse_sample() when handling
PERF_SAMPLE_RAW:

		if (swapped)
			mem_bswap_64((void *) array, data->raw_size);

		array = (void *)array + sizeof(u32);

		OVERFLOW_CHECK(array, data->raw_size, max_size);

Could an attacker provide a maliciously crafted cross-endian perf.data file
with a spoofed raw_size that exceeds the actual event size? Because
mem_bswap_64 performs in-place byte swapping before the OVERFLOW_CHECK
validates the untrusted raw_size, it appears it would blindly read,
byte-swap, and write memory past the event payload boundary.

>  		if (swapped) {
>  			/*
>  			 * struct branch_flag does not have endian
[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903-sympwn-linux-002-final-v2-v1-1-7c6e4166b814@gmail.com?part=1

      reply	other threads:[~2026-09-03 10:21 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 10:08 [PATCH] perf evsel: Validate branch stack before byte swapping Mark Amirkan via B4 Relay
2026-09-03 10:08 ` Mark Amirkan
2026-09-03 10:21 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903102138.A3B191F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=markdamirkan@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.