Steven Rostedt (VMware)
20c2f141b1
tracing / histogram: Fix NULL pointer dereference on strcmp() on NULL event name
[ Upstream commit 5acce0bff2a0420ce87d4591daeb867f47d552c2 ]
The following commands:
# echo 'read_max u64 size;' > synthetic_events
# echo 'hist:keys=common_pid:count=count:onmax($count).trace(read_max,count)' > events/syscalls/sys_enter_read/trigger
Causes:
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] PREEMPT SMP
CPU: 4 PID: 1763 Comm: bash Not tainted 5.14.0-rc2-test+ #155
Hardware name: Hewlett-Packard HP Compaq Pro 6300 SFF/339A, BIOS K01
v03.03 07/14/2016
RIP: 0010:strcmp+0xc/0x20
Code: 75 f7 31 c0 0f b6 0c 06 88 0c 02 48 83 c0 01 84 c9 75 f1 4c 89 c0
c3 0f 1f 80 00 00 00 00 31 c0 eb 08 48 83 c0 01 84 d2 74 0f <0f> b6 14 07
3a 14 06 74 ef 19 c0 83 c8 01 c3 31 c0 c3 66 90 48 89
RSP: 0018:ffffb5fdc0963ca8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffffffb3a4e040 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffff9714c0d0b640 RDI: 0000000000000000
RBP: 0000000000000000 R08: 00000022986b7cde R09: ffffffffb3a4dff8
R10: 0000000000000000 R11: 0000000000000000 R12: ffff9714c50603c8
R13: 0000000000000000 R14: ffff97143fdf9e48 R15: ffff9714c01a2210
FS: 00007f1fa6785740(0000) GS:ffff9714da400000(0000)
knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000002d863004 CR4: 00000000001706e0
Call Trace:
__find_event_file+0x4e/0x80
action_create+0x6b7/0xeb0
? kstrdup+0x44/0x60
event_hist_trigger_func+0x1a07/0x2130
trigger_process_regex+0xbd/0x110
event_trigger_write+0x71/0xd0
vfs_write+0xe9/0x310
ksys_write+0x68/0xe0
do_syscall_64+0x3b/0x90
entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f1fa6879e87
The problem was the "trace(read_max,count)" where the "count" should be
"$count" as "onmax()" only handles variables (although it really should be
able to figure out that "count" is a field of sys_enter_read). But there's
a path that does not find the variable and ends up passing a NULL for the
event, which ends up getting passed to "strcmp()".
Add a check for NULL to return and error on the command with:
# cat error_log
hist:syscalls:sys_enter_read: error: Couldn't create or find variable
Command: hist:keys=common_pid:count=count:onmax($count).trace(read_max,count)
^
Link: https://lkml.kernel.org/r/20210808003011.4037f8d0@oasis.local.home
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: stable@vger.kernel.org
Fixes: 50450603ec tracing: Add 'onmax' hist trigger action support
Reviewed-by: Tom Zanussi <zanussi@kernel.org>
Signed-off-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
|
2021-08-26 08:36:20 -04:00 |
| .. |
|
bpf
|
bpf: Clear zext_dst of dead insns
|
2021-08-26 08:36:17 -04:00 |
|
cgroup
|
cgroup1: fix leaked context root causing sporadic NULL deref in LTP
|
2021-07-31 08:19:37 +02:00 |
|
configs
|
|
|
|
debug
|
kdb: Make memory allocations more robust
|
2021-03-04 10:26:10 +01:00 |
|
dma
|
swiotlb: fix "x86: Don't panic if can not alloc buffer for swiotlb"
|
2020-11-18 19:20:32 +01:00 |
|
events
|
perf: Fix data race between pin_count increment/decrement
|
2021-06-16 11:59:44 +02:00 |
|
gcov
|
gcov: re-fix clang-11+ support
|
2021-04-14 08:24:10 +02:00 |
|
irq
|
genirq/timings: Prevent potential array overflow in __irq_timings_store()
|
2021-08-18 08:57:02 +02:00 |
|
livepatch
|
|
|
|
locking
|
lockding/lockdep: Avoid to find wrong lock dep path in check_irq_usage()
|
2021-07-14 16:53:15 +02:00 |
|
power
|
PM: EM: postpone creating the debugfs dir till fs_initcall
|
2021-03-30 14:35:28 +02:00 |
|
printk
|
printk: fix deadlock when kernel panic
|
2021-03-04 10:26:50 +01:00 |
|
rcu
|
srcu: Fix broken node geometry after early ssp init
|
2021-07-20 16:10:41 +02:00 |
|
sched
|
sched/fair: Fix CFS bandwidth hrtimer expiry type
|
2021-07-25 14:35:13 +02:00 |
|
time
|
timers: Move clearing of base::timer_running under base:: Lock
|
2021-08-12 13:21:03 +02:00 |
|
trace
|
tracing / histogram: Fix NULL pointer dereference on strcmp() on NULL event name
|
2021-08-26 08:36:20 -04:00 |
|
.gitignore
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
acct.c
|
|
|
|
async.c
|
|
|
|
audit.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit.h
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
audit_fsnotify.c
|
|
|
|
audit_tree.c
|
|
|
|
audit_watch.c
|
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
|
2020-10-01 13:17:32 +02:00 |
|
auditfilter.c
|
audit: fix a net reference leak in audit_list_rules_send()
|
2020-06-22 09:30:59 +02:00 |
|
auditsc.c
|
|
|
|
backtracetest.c
|
|
|
|
bounds.c
|
|
|
|
capability.c
|
|
|
|
compat.c
|
|
|
|
configs.c
|
|
|
|
context_tracking.c
|
|
|
|
cpu.c
|
cpu/hotplug: Cure the cpusets trainwreck
|
2021-07-19 08:53:15 +02:00 |
|
cpu_pm.c
|
kernel/cpu_pm: Fix uninitted local in cpu_pm
|
2020-06-22 09:31:22 +02:00 |
|
crash_core.c
|
|
|
|
crash_dump.c
|
|
|
|
cred.c
|
keys: Fix request_key() cache
|
2020-01-17 19:48:42 +01:00 |
|
delayacct.c
|
|
|
|
dma.c
|
|
|
|
exec_domain.c
|
|
|
|
exit.c
|
don't dump the threads that had been already exiting when zapped.
|
2020-11-18 19:20:31 +01:00 |
|
extable.c
|
|
|
|
fail_function.c
|
fail_function: Remove a redundant mutex unlock
|
2020-11-24 13:29:18 +01:00 |
|
fork.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
freezer.c
|
|
|
|
futex.c
|
mm, futex: fix shared futex pgoff on shmem huge page
|
2021-06-30 08:47:55 -04:00 |
|
gen_kheaders.sh
|
kbuild: add variables for compression tools
|
2020-09-03 11:27:10 +02:00 |
|
groups.c
|
|
|
|
hung_task.c
|
|
|
|
iomem.c
|
|
|
|
irq_work.c
|
|
|
|
jump_label.c
|
|
|
|
kallsyms.c
|
kallsyms: Refactor kallsyms_show_value() to take cred
|
2020-07-16 08:16:44 +02:00 |
|
kcmp.c
|
exec: Transform exec_update_mutex into a rw_semaphore
|
2021-01-09 13:44:55 +01:00 |
|
Kconfig.freezer
|
|
|
|
Kconfig.hz
|
|
|
|
Kconfig.locks
|
|
|
|
Kconfig.preempt
|
|
|
|
kcov.c
|
|
|
|
kexec.c
|
|
|
|
kexec_core.c
|
kernel: kexec: remove the lock operation of system_transition_mutex
|
2021-02-03 23:25:56 +01:00 |
|
kexec_elf.c
|
|
|
|
kexec_file.c
|
kernel: kexec_file: fix error return code of kexec_calculate_store_digests()
|
2021-05-19 10:08:28 +02:00 |
|
kexec_internal.h
|
|
|
|
kheaders.c
|
|
|
|
kmod.c
|
kmod: make request_module() return an error when autoloading is disabled
|
2020-04-17 10:50:22 +02:00 |
|
kprobes.c
|
tracing/kprobe: Fix to support kretprobe events on unloaded modules
|
2021-02-13 13:52:54 +01:00 |
|
ksysfs.c
|
|
|
|
kthread.c
|
kthread_worker: fix return value when kthread_mod_delayed_work() races with kthread_cancel_delayed_work_sync()
|
2021-07-14 16:53:19 +02:00 |
|
latencytop.c
|
|
|
|
Makefile
|
kbuild: update config_data.gz only when the content of .config is changed
|
2021-05-11 14:04:16 +02:00 |
|
module-internal.h
|
|
|
|
module.c
|
module: limit enabling module.sig_enforce
|
2021-06-30 08:47:42 -04:00 |
|
module_signature.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
module_signing.c
|
module: harden ELF info handling
|
2021-04-07 14:47:38 +02:00 |
|
notifier.c
|
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
|
2020-10-01 13:17:23 +02:00 |
|
nsproxy.c
|
|
|
|
padata.c
|
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
|
2020-06-17 16:40:22 +02:00 |
|
panic.c
|
|
|
|
params.c
|
|
|
|
pid.c
|
|
|
|
pid_namespace.c
|
|
|
|
profile.c
|
|
|
|
ptrace.c
|
ptrace: make ptrace() fail if the tracee changed its pid unexpectedly
|
2021-05-26 12:05:15 +02:00 |
|
range.c
|
|
|
|
reboot.c
|
reboot: fix overflow parsing reboot cpu number
|
2020-11-18 19:20:30 +01:00 |
|
relay.c
|
kernel/relay.c: fix memleak on destroy relay channel
|
2020-08-26 10:40:51 +02:00 |
|
resource.c
|
/dev/mem: Revoke mappings when a driver claims the region
|
2020-06-24 17:50:35 +02:00 |
|
rseq.c
|
|
|
|
seccomp.c
|
seccomp: Add missing return in non-void function
|
2021-03-04 10:26:45 +01:00 |
|
signal.c
|
ptrace: fix task_join_group_stop() for the case when current is traced
|
2020-11-10 12:37:24 +01:00 |
|
smp.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
smpboot.c
|
kthread: Extract KTHREAD_IS_PER_CPU
|
2021-02-07 15:35:49 +01:00 |
|
smpboot.h
|
|
|
|
softirq.c
|
|
|
|
stackleak.c
|
|
|
|
stacktrace.c
|
|
|
|
stop_machine.c
|
|
|
|
sys.c
|
kernel/sys.c: avoid copying possible padding bytes in copy_to_user
|
2020-10-01 13:17:23 +02:00 |
|
sys_ni.c
|
|
|
|
sysctl-test.c
|
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
|
2020-10-01 13:17:10 +02:00 |
|
sysctl.c
|
sysctl.c: fix underflow value setting risk in vm_table
|
2021-03-17 17:03:45 +01:00 |
|
sysctl_binary.c
|
|
|
|
task_work.c
|
|
|
|
taskstats.c
|
taskstats: fix data-race
|
2020-01-09 10:19:54 +01:00 |
|
test_kprobes.c
|
|
|
|
torture.c
|
|
|
|
tracepoint.c
|
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
|
2021-07-14 16:53:08 +02:00 |
|
tsacct.c
|
|
|
|
ucount.c
|
|
|
|
uid16.c
|
|
|
|
uid16.h
|
|
|
|
umh.c
|
usermodehelper: reset umask to default before executing user process
|
2020-10-14 10:32:58 +02:00 |
|
up.c
|
smp: Fix smp_call_function_single_async prototype
|
2021-05-14 09:44:33 +02:00 |
|
user-return-notifier.c
|
|
|
|
user.c
|
|
|
|
user_namespace.c
|
|
|
|
utsname.c
|
|
|
|
utsname_sysctl.c
|
|
|
|
watchdog.c
|
watchdog/softlockup: Enforce that timestamp is valid on boot
|
2020-02-24 08:36:52 +01:00 |
|
watchdog_hld.c
|
|
|
|
workqueue.c
|
workqueue: fix UAF in pwq_unbound_release_workfn()
|
2021-07-31 08:19:37 +02:00 |
|
workqueue_internal.h
|
|
|