android_kernel_motorola_sm6375/kernel/trace
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Tengda Wu 42561fe62c tracing: Fix use-after-free in print_graph_function_flags during tracer switching
commit 7f81f27b1093e4895e87b74143c59c055c3b1906 upstream.

Kairui reported a UAF issue in print_graph_function_flags() during
ftrace stress testing [1]. This issue can be reproduced if puting a
'mdelay(10)' after 'mutex_unlock(&trace_types_lock)' in s_start(),
and executing the following script:

  $ echo function_graph > current_tracer
  $ cat trace > /dev/null &
  $ sleep 5  # Ensure the 'cat' reaches the 'mdelay(10)' point
  $ echo timerlat > current_tracer

The root cause lies in the two calls to print_graph_function_flags
within print_trace_line during each s_show():

  * One through 'iter->trace->print_line()';
  * Another through 'event->funcs->trace()', which is hidden in
    print_trace_fmt() before print_trace_line returns.

Tracer switching only updates the former, while the latter continues
to use the print_line function of the old tracer, which in the script
above is print_graph_function_flags.

Moreover, when switching from the 'function_graph' tracer to the
'timerlat' tracer, s_start only calls graph_trace_close of the
'function_graph' tracer to free 'iter->private', but does not set
it to NULL. This provides an opportunity for 'event->funcs->trace()'
to use an invalid 'iter->private'.

To fix this issue, set 'iter->private' to NULL immediately after
freeing it in graph_trace_close(), ensuring that an invalid pointer
is not passed to other tracers. Additionally, clean up the unnecessary
'iter->private = NULL' during each 'cat trace' when using wakeup and
irqsoff tracers.

 [1] https://lore.kernel.org/all/20231112150030.84609-1-ryncsn@gmail.com/

Cc: stable@vger.kernel.org
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Zheng Yejian <zhengyejian1@huawei.com>
Link: https://lore.kernel.org/20250320122137.23635-1-wutengda@huaweicloud.com
Fixes: eecb91b9f98d ("tracing: Fix memleak due to race between current_tracer and trace")
Closes: https://lore.kernel.org/all/CAMgjq7BW79KDSCyp+tZHjShSzHsScSiJxn5ffskp-QzVM06fxw@mail.gmail.com/
Reported-by: Kairui Song <kasong@tencent.com>
Signed-off-by: Tengda Wu <wutengda@huaweicloud.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-04-10 14:29:43 +02:00
..
blktrace.c
bpf_trace.c bpf: Use preempt_count() directly in bpf_send_signal_common() 2025-04-10 14:29:40 +02:00
fgraph.c
ftrace.c ftrace: Avoid potential division by zero in function_stat_show() 2025-03-13 12:43:25 +01:00
ftrace_internal.h
Kconfig
Makefile
power-traces.c
preemptirq_delay_test.c tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test 2024-07-05 09:08:25 +02:00
ring_buffer.c ring-buffer: Fix bytes_dropped calculation issue 2025-04-10 14:29:42 +02:00
ring_buffer_benchmark.c
rpm-traces.c
trace.c tracing: Have saved_cmdlines arrays all in one allocation 2024-11-08 16:20:43 +01:00
trace.h tracing: Have trace_event_file have ref counters 2023-11-28 16:50:22 +00:00
trace_benchmark.c
trace_benchmark.h
trace_branch.c
trace_clock.c tracing: Use atomic64_inc_return() in trace_clock_counter() 2024-12-14 19:44:53 +01:00
trace_dynevent.c
trace_dynevent.h
trace_entries.h
trace_event_perf.c trace/trace_event_perf: remove duplicate samples on the first tracepoint event 2024-12-14 19:44:28 +01:00
trace_events.c tracing: Have trace_event_file have ref counters 2023-11-28 16:50:22 +00:00
trace_events_filter.c tracing: Have trace_event_file have ref counters 2023-11-28 16:50:22 +00:00
trace_events_filter_test.h
trace_events_hist.c
trace_events_trigger.c Revert "tracing/trigger: Fix to return error if failed to alloc snapshot" 2024-05-02 16:18:30 +02:00
trace_export.c
trace_functions.c
trace_functions_graph.c tracing: Fix use-after-free in print_graph_function_flags during tracer switching 2025-04-10 14:29:43 +02:00
trace_hwlat.c
trace_irqsoff.c tracing: Fix use-after-free in print_graph_function_flags during tracer switching 2025-04-10 14:29:43 +02:00
trace_kdb.c
trace_kprobe.c tracing/kprobe: Make trace_kprobe's module callback called after jump_label update 2025-01-09 13:23:31 +01:00
trace_kprobe_selftest.c
trace_kprobe_selftest.h
trace_mmiotrace.c
trace_nop.c
trace_output.c tracing: Remove precision vsnprintf() check from print event 2024-11-08 16:20:43 +01:00
trace_output.h
trace_preemptirq.c
trace_printk.c
trace_probe.c tracing: Consider the NULL character when validating the event length 2024-11-08 16:20:51 +01:00
trace_probe.h tracing/kprobes: Return EADDRNOTAVAIL when func matches several symbols 2024-11-08 16:20:47 +01:00
trace_probe_tmpl.h
trace_sched_switch.c
trace_sched_wakeup.c tracing: Fix use-after-free in print_graph_function_flags during tracer switching 2025-04-10 14:29:43 +02:00
trace_selftest.c
trace_selftest_dynamic.c
trace_seq.c
trace_stack.c
trace_stat.c
trace_stat.h
trace_syscalls.c
trace_uprobe.c
tracing_map.c tracing: Fix cmp_entries_dup() to respect sort() comparison rules 2024-12-14 19:44:48 +01:00
tracing_map.h