diff options
| author | Arnaldo Carvalho de Melo <acme@redhat.com> | 2026-07-27 13:17:02 -0300 |
|---|---|---|
| committer | Namhyung Kim <namhyung@kernel.org> | 2026-08-03 12:42:53 -0700 |
| commit | 96fcc9ea5f18c083a1fa73da23afef7e953f7dca (patch) | |
| tree | eb247b54a83b9c3cec73d842a429b44f6b7bf91d /scripts/patch-kernel | |
| parent | ab9c84d1cd59e6b3b73de34982a35a76e3a9b032 (diff) | |
| download | linux-96fcc9ea5f18c083a1fa73da23afef7e953f7dca.tar.gz linux-96fcc9ea5f18c083a1fa73da23afef7e953f7dca.zip | |
perf auxtrace: Fix queue grow overflow and old array leak
auxtrace_queues__grow() has two bugs:
1. When idx is UINT_MAX, the caller passes new_nr_queues = idx + 1 = 0.
The function skips growing (since any nr_queues >= 0), returns
success, and the caller accesses queue_array[UINT_MAX] — an OOB
heap write. Fix by rejecting new_nr_queues == 0 up front.
2. The function allocates a new queue_array via calloc and copies
elements from the old array, but never frees the old array. Fix
by saving the old pointer and freeing it after the copy.
Fixes: e502789302a6ece9 ("perf auxtrace: Add helpers for queuing AUX area tracing data")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Diffstat (limited to 'scripts/patch-kernel')
0 files changed, 0 insertions, 0 deletions
