diff options
| author | Michail Tatas <michail.tatas@gmail.com> | 2026-08-03 10:50:04 +0300 |
|---|---|---|
| committer | Namhyung Kim <namhyung@kernel.org> | 2026-08-03 10:39:13 -0700 |
| commit | 9d393ca644cd6c827f5dfae09c99f585d981bf4c (patch) | |
| tree | fe15658d63b9a03b333680f642294277c1766850 | |
| parent | dbd2505061349bbee9c3282472f14ae27da8adfd (diff) | |
| download | linux-9d393ca644cd6c827f5dfae09c99f585d981bf4c.tar.gz linux-9d393ca644cd6c827f5dfae09c99f585d981bf4c.zip | |
perf ftrace: Fix leak in parse_filter_event
strsep() advances the pointer given to it. After the loop s is
either NULL (on success) or points mid buffer (early exit if malloc
fails) so the original buffer is never freed properly.
Fix by adding a tmp pointer for use by strsep and free the original
pointer
Signed-off-by: Michail Tatas <michail.tatas@gmail.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
| -rw-r--r-- | tools/perf/builtin-ftrace.c | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/tools/perf/builtin-ftrace.c b/tools/perf/builtin-ftrace.c index f7126196b092..4f881a40c311 100644 --- a/tools/perf/builtin-ftrace.c +++ b/tools/perf/builtin-ftrace.c @@ -1607,14 +1607,15 @@ static int parse_filter_event(const struct option *opt, const char *str, { struct list_head *head = opt->value; struct filter_entry *entry; - char *s, *p; + char *s, *p, *tmp; int ret = -ENOMEM; s = strdup(str); if (s == NULL) return -ENOMEM; - while ((p = strsep(&s, ",")) != NULL) { + tmp = s; + while ((p = strsep(&tmp, ",")) != NULL) { entry = malloc(sizeof(*entry) + strlen(p) + 1); if (entry == NULL) goto out; |
