From: Greg Kroah-Hartman Date: Wed, 29 Jul 2026 13:37:00 +0000 (+0200) Subject: 5.10-stable patches X-Git-Tag: v6.1.179~26 X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=36bd3201bb2c6413875d72362b04f92d43af5cd6;p=thirdparty%2Fkernel%2Fstable-queue.git 5.10-stable patches added patches: arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch cdrom-fix-stack-out-of-bounds-read-in-cdromvolctrl.patch comedi-comedi_parport-deal-with-premature-interrupt.patch intel_th-fix-msc-output-device-reference-leak.patch revert-arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch tracing-fix-mmiotrace-possible-null-dereferencing-of-hiter-dev.patch tracing-fix-resource-leak-on-mmiotrace-trace_pipe-close.patch tracing-probes-avoid-temporary-buffer-truncation-in-trace_probe_match_command_args.patch tracing-probes-fix-potential-underflow-in-len_or_zero-macro.patch tracing-probes-prevent-out-of-bounds-write-in-__trace_probe_log_err.patch --- diff --git a/queue-5.10/arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch b/queue-5.10/arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch new file mode 100644 index 0000000000..c69908e730 --- /dev/null +++ b/queue-5.10/arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch @@ -0,0 +1,104 @@ +From e057b94772328221405b067c3a85fe479b915dc8 Mon Sep 17 00:00:00 2001 +From: Will Deacon +Date: Thu, 16 Jul 2026 13:06:39 +0100 +Subject: arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates + +From: Will Deacon + +commit e057b94772328221405b067c3a85fe479b915dc8 upstream. + +When seccomp support was originally added to arm64 in a1ae65b21941 +("arm64: add seccomp support"), seccomp was erroneously called _before_ +the ptrace syscall-enter-stop and therefore the tracer could trivially +manipulate the syscall register state after the seccomp check had +passed. This was subsequently fixed in a5cd110cb836 ("arm64/ptrace: run +seccomp after ptrace") by moving the seccomp check after the tracer has +run. Unfortunately, a decade later, that fix has been reported to be +incomplete. + +On arm64, both the first argument to a syscall and its eventual return +value are allocated to register x0. In order to facilitate syscall +restarting and querying of syscall arguments on the syscall exit path, +the original value of x0 is stashed in 'struct pt_regs::orig_x0' early +during the syscall entry path and is returned for the first argument by +syscall_get_arguments(). Unlike 32-bit Arm, this stashed value is not +directly exposed via ptrace() and so changes to register x0 made by the +tracer on a syscall-enter-stop are not reflected in 'orig_x0'. This +means that seccomp, syscall tracepoints and audit can observe a stale +value for the register compared to the argument that will be observed by +the actual syscall. + +Re-sync 'orig_x0' from x0 on the syscall entry path following a +potential ptrace stop (i.e. PTRACE_EVENTMSG_SYSCALL_ENTRY or +SECCOMP_RET_TRACE). This behaviour is limited to native tasks (because +compat tasks expose 'orig_r0' to ptrace) where the syscall is not being +skipped (because x0 is updated to hold the return value of -ENOSYS in +that case). + +Cc: Kees Cook +Cc: Jinjie Ruan +Cc: Mark Rutland +Cc: stable@vger.kernel.org +Reported-by: Yiqi Sun +Link: https://lore.kernel.org/all/20260529065444.1336608-1-sunyiqixm@gmail.com/ +Suggested-by: Catalin Marinas +Fixes: a5cd110cb836 ("arm64/ptrace: run seccomp after ptrace") +Reviewed-by: Jinjie Ruan +Tested-by: Jinjie Ruan +Signed-off-by: Will Deacon +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kernel/ptrace.c | 29 +++++++++++++++++++++++++++++ + 1 file changed, 29 insertions(+) + +--- a/arch/arm64/kernel/ptrace.c ++++ b/arch/arm64/kernel/ptrace.c +@@ -1797,6 +1797,21 @@ static void tracehook_report_syscall(str + } + } + ++static void update_syscall_orig_x0_after_ptrace(struct pt_regs *regs) ++{ ++ /* ++ * Keep orig_x0 authoritative so that seccomp (via ++ * syscall_get_arguments()), audit and the restart path all see the same ++ * first argument the syscall is dispatched with, even if it has been ++ * updated by a tracer. Skip this for NO_SYSCALL (set either by the user ++ * or the tracer), as regs[0] holds the return value (see the comment in ++ * el0_svc_common()) and can be unwound using syscall_rollback(). ++ * For compat tasks, orig_r0 is provided directly through GPR index 17. ++ */ ++ if (!is_compat_task() && regs->syscallno != NO_SYSCALL) ++ regs->orig_x0 = regs->regs[0]; ++} ++ + int syscall_trace_enter(struct pt_regs *regs) + { + unsigned long flags = READ_ONCE(current_thread_info()->flags); +@@ -1805,12 +1820,26 @@ int syscall_trace_enter(struct pt_regs * + tracehook_report_syscall(regs, PTRACE_SYSCALL_ENTER); + if (flags & _TIF_SYSCALL_EMU) + return NO_SYSCALL; ++ ++ /* ++ * Ensure ptrace changes to x0 during a regular ++ * syscall-enter-stop (PTRACE_SYSCALL) are visible to ++ * subsequent seccomp checks, tracepoints and audit. ++ */ ++ update_syscall_orig_x0_after_ptrace(regs); + } + + /* Do the secure computing after ptrace; failures should be fast. */ + if (secure_computing() == -1) + return NO_SYSCALL; + ++ /* ++ * Ensure tracer changes to x0 during seccomp ptrace exit ++ * processing (SECCOMP_RET_TRACE) are visible to tracepoints and ++ * audit. ++ */ ++ update_syscall_orig_x0_after_ptrace(regs); ++ + if (test_thread_flag(TIF_SYSCALL_TRACEPOINT)) + trace_sys_enter(regs, regs->syscallno); + diff --git a/queue-5.10/cdrom-fix-stack-out-of-bounds-read-in-cdromvolctrl.patch b/queue-5.10/cdrom-fix-stack-out-of-bounds-read-in-cdromvolctrl.patch new file mode 100644 index 0000000000..d29f924eb1 --- /dev/null +++ b/queue-5.10/cdrom-fix-stack-out-of-bounds-read-in-cdromvolctrl.patch @@ -0,0 +1,54 @@ +From b27e195d4db8dea263050bdbeb11881b2999c9c6 Mon Sep 17 00:00:00 2001 +From: Xu Rao +Date: Mon, 20 Jul 2026 20:44:21 +0100 +Subject: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL + +From: Xu Rao + +commit b27e195d4db8dea263050bdbeb11881b2999c9c6 upstream. + +mmc_ioctl_cdrom_volume() first reads the audio control mode page into a +32-byte stack buffer with cgc->buflen set to 24. If the device reports a +block descriptor, the function increases cgc->buflen to include that +descriptor and reads the page again. + +For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list +by moving cgc->buffer forward by offset - 8 bytes. This drops the block +descriptor from the outgoing payload and leaves a new 8-byte mode +parameter header in front of the audio control page. However, cgc->buflen +is left unchanged. + +With a standard 8-byte block descriptor, cgc->buffer points at buffer + 8 +but cgc->buflen remains 32. cdrom_mode_select() therefore asks the low +level packet path to write 32 bytes from that adjusted pointer, reading 8 +bytes past the end of the 32-byte stack buffer. + +This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on +drives that return a non-zero block descriptor length, which helps explain +why it has gone unnoticed. The overread is also sent to the device as +extra MODE SELECT payload, so it may not produce an obvious local failure. + +Reduce cgc->buflen by the same amount as the buffer pointer adjustment so +the MODE SELECT transfer covers only the intended parameter list. + +Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") +Cc: stable@vger.kernel.org +Signed-off-by: Xu Rao +Signed-off-by: Phillip Potter +Link: https://patch.msgid.link/20260720194421.1497-2-phil@philpotter.co.uk +Signed-off-by: Jens Axboe +Signed-off-by: Greg Kroah-Hartman +--- + drivers/cdrom/cdrom.c | 1 + + 1 file changed, 1 insertion(+) + +--- a/drivers/cdrom/cdrom.c ++++ b/drivers/cdrom/cdrom.c +@@ -3218,6 +3218,7 @@ static noinline int mmc_ioctl_cdrom_volu + + /* set volume */ + cgc->buffer = buffer + offset - 8; ++ cgc->buflen -= offset - 8; + memset(cgc->buffer, 0, 8); + return cdrom_mode_select(cdi, cgc); + } diff --git a/queue-5.10/comedi-comedi_parport-deal-with-premature-interrupt.patch b/queue-5.10/comedi-comedi_parport-deal-with-premature-interrupt.patch new file mode 100644 index 0000000000..2e916a034a --- /dev/null +++ b/queue-5.10/comedi-comedi_parport-deal-with-premature-interrupt.patch @@ -0,0 +1,76 @@ +From 17221216ae8ce6a24e8a4e787382e3ebc81b88a8 Mon Sep 17 00:00:00 2001 +From: Ian Abbott +Date: Wed, 27 May 2026 13:51:03 +0100 +Subject: comedi: comedi_parport: deal with premature interrupt + +From: Ian Abbott + +commit 17221216ae8ce6a24e8a4e787382e3ebc81b88a8 upstream. + +Syzbot reported a general protection fault in +`comedi_get_is_subdevice_running()`, which was called from the interrupt +handler `parport_interrupt()` in the "comedi_parport" driver, but it +does not currently have a C reproducer for the problem. It's +probably due to a premature interrupt for one of two reasons: + +1. The driver sets up the interrupt handler before the comedi subdevices + used by the interrupt handler have been allocated, but does not + disable the interrupt in the parallel port's CTRL register first. +2. The driver uses a user-supplied I/O port base address which Syzbot + would have supplied, but it might not be backed by real parallel port + hardware. + +Change the initialization order in the driver's comedi "attach" handler +(`parport_attach()`) so that the hardware registers are initialized +before the interrupt handler is requested. This should prevent +premature interrupts occurring for real hardware. + +Also add a test to the interrupt handler to ensure the comedi device is +fully attached and return early if it isn't. + +Fixes: 241ab6ad7108e ("Staging: comedi: add comedi_parport driver") +Reported-by: syzbot+f24c3d5d316011bacc70@syzkaller.appspotmail.com +Cc: stable +Signed-off-by: Ian Abbott +Link: https://patch.msgid.link/20260527125104.96596-1-abbotti@mev.co.uk +Signed-off-by: Greg Kroah-Hartman +--- + drivers/staging/comedi/drivers/comedi_parport.c | 13 ++++++++++--- + 1 file changed, 10 insertions(+), 3 deletions(-) + +--- a/drivers/staging/comedi/drivers/comedi_parport.c ++++ b/drivers/staging/comedi/drivers/comedi_parport.c +@@ -211,6 +211,13 @@ static irqreturn_t parport_interrupt(int + struct comedi_subdevice *s = dev->read_subdev; + unsigned int ctrl; + ++ /* ++ * Check device is fully attached. Device interrupts should have ++ * been disabled, but do this in case of bad hardware. ++ */ ++ if (!dev->attached) ++ return IRQ_NONE; ++ + ctrl = inb(dev->iobase + PARPORT_CTRL_REG); + if (!(ctrl & PARPORT_CTRL_IRQ_ENA)) + return IRQ_NONE; +@@ -231,6 +238,9 @@ static int parport_attach(struct comedi_ + if (ret) + return ret; + ++ outb(0, dev->iobase + PARPORT_DATA_REG); ++ outb(0, dev->iobase + PARPORT_CTRL_REG); ++ + if (it->options[1]) { + ret = request_irq(it->options[1], parport_interrupt, 0, + dev->board_name, dev); +@@ -286,9 +296,6 @@ static int parport_attach(struct comedi_ + s->cancel = parport_intr_cancel; + } + +- outb(0, dev->iobase + PARPORT_DATA_REG); +- outb(0, dev->iobase + PARPORT_CTRL_REG); +- + return 0; + } + diff --git a/queue-5.10/intel_th-fix-msc-output-device-reference-leak.patch b/queue-5.10/intel_th-fix-msc-output-device-reference-leak.patch new file mode 100644 index 0000000000..661c4f159f --- /dev/null +++ b/queue-5.10/intel_th-fix-msc-output-device-reference-leak.patch @@ -0,0 +1,74 @@ +From 761b785a0cfbce43761227bc42a7f984f31f8921 Mon Sep 17 00:00:00 2001 +From: Guangshuo Li +Date: Wed, 15 Jul 2026 15:08:51 +0800 +Subject: intel_th: fix MSC output device reference leak + +From: Guangshuo Li + +commit 761b785a0cfbce43761227bc42a7f984f31f8921 upstream. + +intel_th_output_open() looks up the output device with +bus_find_device_by_devt(), which returns the device with a reference that +must be dropped after use. + +commit 95fc36a234da ("intel_th: fix device leak on output open()") +attempted to drop the reference from intel_th_output_release(). However, +a successful open replaces file->f_op with the output driver file +operations before returning, so close runs the output driver release +callback instead. + +For MSC outputs, close runs intel_th_msc_release(), which only removes +the per-file iterator and does not drop the device reference taken by +intel_th_output_open(). Consequently, every successful MSC output open +leaks one device reference. + +Drop the device reference from intel_th_msc_release(), which is the +release path actually used for MSC output files. Remove the now-unused +intel_th_output_release() callback from intel_th_output_fops. + +Fixes: 95fc36a234da ("intel_th: fix device leak on output open()") +Cc: stable +Signed-off-by: Guangshuo Li +Reviewed-by: Johan Hovold +Link: https://patch.msgid.link/20260715070851.2077965-1-lgs201920130244@gmail.com +Signed-off-by: Greg Kroah-Hartman +Signed-off-by: Greg Kroah-Hartman +--- + drivers/hwtracing/intel_th/core.c | 10 ---------- + drivers/hwtracing/intel_th/msu.c | 2 ++ + 2 files changed, 2 insertions(+), 10 deletions(-) + +--- a/drivers/hwtracing/intel_th/core.c ++++ b/drivers/hwtracing/intel_th/core.c +@@ -843,18 +843,8 @@ out_put_device: + return err; + } + +-static int intel_th_output_release(struct inode *inode, struct file *file) +-{ +- struct intel_th_device *thdev = file->private_data; +- +- put_device(&thdev->dev); +- +- return 0; +-} +- + static const struct file_operations intel_th_output_fops = { + .open = intel_th_output_open, +- .release = intel_th_output_release, + .llseek = noop_llseek, + }; + +--- a/drivers/hwtracing/intel_th/msu.c ++++ b/drivers/hwtracing/intel_th/msu.c +@@ -1463,8 +1463,10 @@ static int intel_th_msc_release(struct i + { + struct msc_iter *iter = file->private_data; + struct msc *msc = iter->msc; ++ struct intel_th_device *thdev = msc->thdev; + + msc_iter_remove(iter, msc); ++ put_device(&thdev->dev); + + return 0; + } diff --git a/queue-5.10/revert-arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch b/queue-5.10/revert-arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch new file mode 100644 index 0000000000..89510abec9 --- /dev/null +++ b/queue-5.10/revert-arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch @@ -0,0 +1,81 @@ +From 26b483d52417253d88a3a01262ac85914a7aec8e Mon Sep 17 00:00:00 2001 +From: Will Deacon +Date: Fri, 17 Jul 2026 17:25:58 +0100 +Subject: Revert "arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates" + +From: Will Deacon + +commit 26b483d52417253d88a3a01262ac85914a7aec8e upstream. + +This reverts commit e057b94772328221405b067c3a85fe479b915dc8. + +Sashiko points out that updating 'orig_x0' after secure_computing() +has returned is too late to handle the case where a seccomp filter is +re-evaluated after initially returning SECCOMP_RET_TRACE. This means +that a tracer can manipulate the first argument of the syscall behind +seccomp's back. + +For now, revert the initial fix and we'll have another crack at it soon. +Since the incorrect fix was cc'd to stable, do the same here with an +appropriate fixes tag. + +Cc: stable@vger.kernel.org +Fixes: e057b9477232 ("arm64: syscall: Ensure saved x0 is kept in-sync with tracer updates") +Link: https://sashiko.dev/#/patchset/20260716120640.6590-1-will@kernel.org +Signed-off-by: Will Deacon +Signed-off-by: Greg Kroah-Hartman +--- + arch/arm64/kernel/ptrace.c | 29 ----------------------------- + 1 file changed, 29 deletions(-) + +--- a/arch/arm64/kernel/ptrace.c ++++ b/arch/arm64/kernel/ptrace.c +@@ -1797,21 +1797,6 @@ static void tracehook_report_syscall(str + } + } + +-static void update_syscall_orig_x0_after_ptrace(struct pt_regs *regs) +-{ +- /* +- * Keep orig_x0 authoritative so that seccomp (via +- * syscall_get_arguments()), audit and the restart path all see the same +- * first argument the syscall is dispatched with, even if it has been +- * updated by a tracer. Skip this for NO_SYSCALL (set either by the user +- * or the tracer), as regs[0] holds the return value (see the comment in +- * el0_svc_common()) and can be unwound using syscall_rollback(). +- * For compat tasks, orig_r0 is provided directly through GPR index 17. +- */ +- if (!is_compat_task() && regs->syscallno != NO_SYSCALL) +- regs->orig_x0 = regs->regs[0]; +-} +- + int syscall_trace_enter(struct pt_regs *regs) + { + unsigned long flags = READ_ONCE(current_thread_info()->flags); +@@ -1820,26 +1805,12 @@ int syscall_trace_enter(struct pt_regs * + tracehook_report_syscall(regs, PTRACE_SYSCALL_ENTER); + if (flags & _TIF_SYSCALL_EMU) + return NO_SYSCALL; +- +- /* +- * Ensure ptrace changes to x0 during a regular +- * syscall-enter-stop (PTRACE_SYSCALL) are visible to +- * subsequent seccomp checks, tracepoints and audit. +- */ +- update_syscall_orig_x0_after_ptrace(regs); + } + + /* Do the secure computing after ptrace; failures should be fast. */ + if (secure_computing() == -1) + return NO_SYSCALL; + +- /* +- * Ensure tracer changes to x0 during seccomp ptrace exit +- * processing (SECCOMP_RET_TRACE) are visible to tracepoints and +- * audit. +- */ +- update_syscall_orig_x0_after_ptrace(regs); +- + if (test_thread_flag(TIF_SYSCALL_TRACEPOINT)) + trace_sys_enter(regs, regs->syscallno); + diff --git a/queue-5.10/series b/queue-5.10/series index 128280fb28..bf12b0f2dc 100644 --- a/queue-5.10/series +++ b/queue-5.10/series @@ -147,3 +147,13 @@ wifi-brcmfmac-make-release_scratchbuffers-idempotent.patch bluetooth-rfcomm-fix-session-uaf-in-set_termios.patch exec-fix-unsigned-loop-counter-wrap-in-transfer_args_to_stack.patch binfmt_misc-set-have_execfd-only-once-the-interpreter-is-opened.patch +cdrom-fix-stack-out-of-bounds-read-in-cdromvolctrl.patch +comedi-comedi_parport-deal-with-premature-interrupt.patch +intel_th-fix-msc-output-device-reference-leak.patch +tracing-fix-mmiotrace-possible-null-dereferencing-of-hiter-dev.patch +tracing-fix-resource-leak-on-mmiotrace-trace_pipe-close.patch +tracing-probes-avoid-temporary-buffer-truncation-in-trace_probe_match_command_args.patch +tracing-probes-fix-potential-underflow-in-len_or_zero-macro.patch +tracing-probes-prevent-out-of-bounds-write-in-__trace_probe_log_err.patch +arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch +revert-arm64-syscall-ensure-saved-x0-is-kept-in-sync-with-tracer-updates.patch diff --git a/queue-5.10/tracing-fix-mmiotrace-possible-null-dereferencing-of-hiter-dev.patch b/queue-5.10/tracing-fix-mmiotrace-possible-null-dereferencing-of-hiter-dev.patch new file mode 100644 index 0000000000..0e694141ef --- /dev/null +++ b/queue-5.10/tracing-fix-mmiotrace-possible-null-dereferencing-of-hiter-dev.patch @@ -0,0 +1,38 @@ +From 144f29e85702234b23d2a62abf723e6a17eb5427 Mon Sep 17 00:00:00 2001 +From: Steven Rostedt +Date: Tue, 21 Jul 2026 21:11:43 -0400 +Subject: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev + +From: Steven Rostedt + +commit 144f29e85702234b23d2a62abf723e6a17eb5427 upstream. + +If the mmio_pipe_open() fails to find a PCI device, the hiter->dev +will be assigned to NULL. The mmiotrace read() function dereferences the +hiter->dev if hiter exists. + +Change the test of the read to not only check hiter being NULL, but also +the hiter->dev before dereferencing it. + +Cc: stable@vger.kernel.org +Link: https://patch.msgid.link/20260721211143.36dbd559@gandalf.local.home +Fixes: f984b51e0779 ("ftrace: add mmiotrace plugin") +Reported-by: Sashiko +Link: https://sashiko.dev/#/patchset/20260715143604.14481-1-gaikwad.dcg%40gmail.com +Signed-off-by: Steven Rostedt +Signed-off-by: Greg Kroah-Hartman +--- + kernel/trace/trace_mmiotrace.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/kernel/trace/trace_mmiotrace.c ++++ b/kernel/trace/trace_mmiotrace.c +@@ -148,7 +148,7 @@ static ssize_t mmio_read(struct trace_it + goto print_out; + } + +- if (!hiter) ++ if (!hiter || !hiter->dev) + return 0; + + mmio_print_pcidev(s, hiter->dev); diff --git a/queue-5.10/tracing-fix-resource-leak-on-mmiotrace-trace_pipe-close.patch b/queue-5.10/tracing-fix-resource-leak-on-mmiotrace-trace_pipe-close.patch new file mode 100644 index 0000000000..0f1eec1ead --- /dev/null +++ b/queue-5.10/tracing-fix-resource-leak-on-mmiotrace-trace_pipe-close.patch @@ -0,0 +1,62 @@ +From c1d87e724ae55e781b7cc7ccafb34d9e668582b2 Mon Sep 17 00:00:00 2001 +From: deepakraog +Date: Wed, 15 Jul 2026 20:06:04 +0530 +Subject: tracing: Fix resource leak on mmiotrace trace_pipe close + +From: deepakraog + +commit c1d87e724ae55e781b7cc7ccafb34d9e668582b2 upstream. + +The mmiotrace tracer was added May 12th 2008. At that time, resources +created in pipe_open() could not be freed because there was not +pipe_close function pointer of the tracer. The pipe_close function pointer +was added in December 7th, 2009, but the mmiotrace tracer was not updated. + +mmio_pipe_open() allocates a header_iter and takes a pci_dev reference +when trace_pipe is opened. mmio_close() frees them, but it was only +wired to the tracer's .close callback. + +tracing_release_pipe() invokes .pipe_close, not .close, when the +trace_pipe file is released. As a result, closing trace_pipe with the +mmiotrace tracer active leaked the header_iter allocation and left a +stale pci_dev reference. + +Set .pipe_close to mmio_close, matching how function_graph wires both +callbacks to the same handler. + +Note, if the trace_pipe is read to completion, it will clean up the +resources, but if one were to run: + + # head -n 1 /sys/kernel/tracing/trace_pipe + VERSION 20070824 + +Over and over again, it would trigger a massive leak. + +Cc: stable@vger.kernel.org +Fixes: c521efd1700a8 ("tracing: Add pipe_close interface) +Link: https://patch.msgid.link/20260715143604.14481-1-gaikwad.dcg@gmail.com +Signed-off-by: deepakraog +Signed-off-by: Steven Rostedt +Signed-off-by: Greg Kroah-Hartman +--- + kernel/trace/trace_mmiotrace.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/kernel/trace/trace_mmiotrace.c ++++ b/kernel/trace/trace_mmiotrace.c +@@ -111,7 +111,6 @@ static void mmio_pipe_open(struct trace_ + iter->private = hiter; + } + +-/* XXX: This is not called when the pipe is closed! */ + static void mmio_close(struct trace_iterator *iter) + { + struct header_iter *hiter = iter->private; +@@ -281,6 +280,7 @@ static struct tracer mmio_tracer __read_ + .start = mmio_trace_start, + .pipe_open = mmio_pipe_open, + .close = mmio_close, ++ .pipe_close = mmio_close, + .read = mmio_read, + .print_line = mmio_print_line, + .noboot = true, diff --git a/queue-5.10/tracing-probes-avoid-temporary-buffer-truncation-in-trace_probe_match_command_args.patch b/queue-5.10/tracing-probes-avoid-temporary-buffer-truncation-in-trace_probe_match_command_args.patch new file mode 100644 index 0000000000..c3e9e6f912 --- /dev/null +++ b/queue-5.10/tracing-probes-avoid-temporary-buffer-truncation-in-trace_probe_match_command_args.patch @@ -0,0 +1,53 @@ +From 15f197856d68882af9416fc97516bb55079b7677 Mon Sep 17 00:00:00 2001 +From: "Masami Hiramatsu (Google)" +Date: Mon, 20 Jul 2026 19:12:10 +0900 +Subject: tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args() + +From: Masami Hiramatsu (Google) + +commit 15f197856d68882af9416fc97516bb55079b7677 upstream. + +In trace_probe_match_command_args(), a stack buffer buf[MAX_ARGSTR_LEN + 1] +(256 bytes) is used to format "=". However, since name can +be up to 32 bytes (MAX_ARG_NAME_LEN) and comm up to 255 bytes +(MAX_ARGSTR_LEN), the formatted string can exceed 256 bytes and get +truncated by snprintf(), causing spurious argument matching failures. + +Instead of formatting into a temporary buffer on stack, compare the +argument name, the '=' delimiter, and the comm expression directly. + +Link: https://lore.kernel.org/all/178454233010.290363.10428767141343428804.stgit@devnote2/ + +Fixes: eb5bf81330a7 ("tracing/kprobe: Add per-probe delete from event") +Cc: stable@vger.kernel.org +Assisted-by: Antigravity:gemini-3.5-flash +Signed-off-by: Masami Hiramatsu (Google) +Signed-off-by: Greg Kroah-Hartman +--- + kernel/trace/trace_probe.c | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +--- a/kernel/trace/trace_probe.c ++++ b/kernel/trace/trace_probe.c +@@ -1150,16 +1150,17 @@ int trace_probe_compare_arg_type(struct + bool trace_probe_match_command_args(struct trace_probe *tp, + int argc, const char **argv) + { +- char buf[MAX_ARGSTR_LEN + 1]; + int i; + + if (tp->nr_args < argc) + return false; + + for (i = 0; i < argc; i++) { +- snprintf(buf, sizeof(buf), "%s=%s", +- tp->args[i].name, tp->args[i].comm); +- if (strcmp(buf, argv[i])) ++ int len = strlen(tp->args[i].name); ++ ++ if (strncmp(argv[i], tp->args[i].name, len) || ++ argv[i][len] != '=' || ++ strcmp(argv[i] + len + 1, tp->args[i].comm)) + return false; + } + return true; diff --git a/queue-5.10/tracing-probes-fix-potential-underflow-in-len_or_zero-macro.patch b/queue-5.10/tracing-probes-fix-potential-underflow-in-len_or_zero-macro.patch new file mode 100644 index 0000000000..1b10574cb4 --- /dev/null +++ b/queue-5.10/tracing-probes-fix-potential-underflow-in-len_or_zero-macro.patch @@ -0,0 +1,38 @@ +From 8ce20bfba48902e1382187cd1a852f7cf3a1e739 Mon Sep 17 00:00:00 2001 +From: "Masami Hiramatsu (Google)" +Date: Mon, 20 Jul 2026 19:12:29 +0900 +Subject: tracing/probes: Fix potential underflow in LEN_OR_ZERO macro + +From: Masami Hiramatsu (Google) + +commit 8ce20bfba48902e1382187cd1a852f7cf3a1e739 upstream. + +In __set_print_fmt(), LEN_OR_ZERO is defined as (len ? len - pos : 0). +If len is non-zero but smaller than pos, len - pos evaluates to a negative +integer. When passed as a size argument to snprintf(), this negative value +is cast to a large unsigned size_t, bypassing buffer size limits. + +Ensure len > pos before subtracting to avoid integer underflow. + +Link: https://lore.kernel.org/all/178454234934.290363.15247317871499514139.stgit@devnote2/ + +Fixes: 5bf652aaf46c ("tracing/probes: Integrate duplicate set_print_fmt()") +Cc: stable@vger.kernel.org +Assisted-by: Antigravity:gemini-3.5-flash +Signed-off-by: Masami Hiramatsu (Google) +Signed-off-by: Greg Kroah-Hartman +--- + kernel/trace/trace_probe.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/kernel/trace/trace_probe.c ++++ b/kernel/trace/trace_probe.c +@@ -842,7 +842,7 @@ int traceprobe_update_arg(struct probe_a + } + + /* When len=0, we just calculate the needed length */ +-#define LEN_OR_ZERO (len ? len - pos : 0) ++#define LEN_OR_ZERO (len > pos ? len - pos : 0) + static int __set_print_fmt(struct trace_probe *tp, char *buf, int len, + bool is_return) + { diff --git a/queue-5.10/tracing-probes-prevent-out-of-bounds-write-in-__trace_probe_log_err.patch b/queue-5.10/tracing-probes-prevent-out-of-bounds-write-in-__trace_probe_log_err.patch new file mode 100644 index 0000000000..62d22ee8f0 --- /dev/null +++ b/queue-5.10/tracing-probes-prevent-out-of-bounds-write-in-__trace_probe_log_err.patch @@ -0,0 +1,38 @@ +From a9d6fb284039a5d3858a1d9f9a0d7e46cfb7c2d4 Mon Sep 17 00:00:00 2001 +From: "Masami Hiramatsu (Google)" +Date: Mon, 20 Jul 2026 19:12:20 +0900 +Subject: tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err() + +From: Masami Hiramatsu (Google) + +commit a9d6fb284039a5d3858a1d9f9a0d7e46cfb7c2d4 upstream. + +If trace_probe_log.argc is 0 in __trace_probe_log_err(), the loop +constructing the command string will not execute and p will remain equal to +command. Writing to *(p - 1) will cause an out-of-bounds access before +command. This should not happen, but better to be treated. + +Reject if trace_probe_log.argc is 0. + +Link: https://lore.kernel.org/all/178454233992.290363.18323091580600697731.stgit@devnote2/ + +Fixes: ab105a4fb894 ("tracing: Use tracing error_log with probe events") +Cc: stable@vger.kernel.org +Assisted-by: Antigravity:gemini-3.5-flash +Signed-off-by: Masami Hiramatsu (Google) +Signed-off-by: Greg Kroah-Hartman +--- + kernel/trace/trace_probe.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +--- a/kernel/trace/trace_probe.c ++++ b/kernel/trace/trace_probe.c +@@ -165,7 +165,7 @@ void __trace_probe_log_err(int offset, i + char *command, *p; + int i, len = 0, pos = 0; + +- if (!trace_probe_log.argv) ++ if (!trace_probe_log.argv || !trace_probe_log.argc) + return; + + /* Recalcurate the length and allocate buffer */