mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
tracing/probes: Avoid temporary buffer truncation in trace_probe_match_command_args()
commit15f197856dupstream. In trace_probe_match_command_args(), a stack buffer buf[MAX_ARGSTR_LEN + 1] (256 bytes) is used to format "<name>=<comm>". However, since name can be up to 32 bytes (MAX_ARG_NAME_LEN) and comm up to 255 bytes (MAX_ARGSTR_LEN), the formatted string can exceed 256 bytes and get truncated by snprintf(), causing spurious argument matching failures. Instead of formatting into a temporary buffer on stack, compare the argument name, the '=' delimiter, and the comm expression directly. Link: https://lore.kernel.org/all/178454233010.290363.10428767141343428804.stgit@devnote2/ Fixes:eb5bf81330("tracing/kprobe: Add per-probe delete from event") Cc: stable@vger.kernel.org Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
08259252e0
commit
707720ab00
@@ -2105,16 +2105,17 @@ int trace_probe_compare_arg_type(struct trace_probe *a, struct trace_probe *b)
|
||||
bool trace_probe_match_command_args(struct trace_probe *tp,
|
||||
int argc, const char **argv)
|
||||
{
|
||||
char buf[MAX_ARGSTR_LEN + 1];
|
||||
int i;
|
||||
|
||||
if (tp->nr_args < argc)
|
||||
return false;
|
||||
|
||||
for (i = 0; i < argc; i++) {
|
||||
snprintf(buf, sizeof(buf), "%s=%s",
|
||||
tp->args[i].name, tp->args[i].comm);
|
||||
if (strcmp(buf, argv[i]))
|
||||
int len = strlen(tp->args[i].name);
|
||||
|
||||
if (strncmp(argv[i], tp->args[i].name, len) ||
|
||||
argv[i][len] != '=' ||
|
||||
strcmp(argv[i] + len + 1, tp->args[i].comm))
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
|
||||
Reference in New Issue
Block a user