diff options
| author | Zhengchuan Liang <zcliangcn@gmail.com> | 2026-09-28 10:59:35 -0700 |
|---|---|---|
| committer | Peter Zijlstra <peterz@infradead.org> | 2026-10-01 14:02:06 +0200 |
| commit | 357e8a77a501d96c9517f01f4a211eed5e9c9184 (patch) | |
| tree | bbdffc21a20e1ec35170513edb5de6df22101985 | |
| parent | b9d1fdc6f4ac1b6e49f9deafaf137da1407d9af1 (diff) | |
| download | linux-stable-357e8a77a501d96c9517f01f4a211eed5e9c9184.tar.gz linux-stable-357e8a77a501d96c9517f01f4a211eed5e9c9184.zip | |
perf: Require kernel access for text poke events
Perf events with exclude_kernel=1 can be opened without kernel perf
access. However, exclude_kernel does not suppress text-poke sideband
records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL
and contains a raw kernel instruction address.
An unprivileged task can therefore open and mmap a task-local software
event with text_poke=1. Both opening a count-only tracepoint event and
configuring UDP GRO for ESP-in-UDP cause updates to inline static calls;
the observer receives the relocated addresses of the modified instructions.
For a known kernel image, any such address reveals the runtime kernel
text base despite KASLR.
Call perf_allow_kernel() whenever attr.text_poke is set, regardless of
exclude_kernel. Events that neither monitor kernel execution nor request
text-poke records retain their existing permissions.
Fixes: e17d43b93e54 ("perf: Add perf text poke event")
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/99131354c41e23188f778b92f90363775b482395.1790573390.git.zcliangcn@gmail.com
| -rw-r--r-- | kernel/events/core.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/kernel/events/core.c b/kernel/events/core.c index 3aa223595..7846d70be 100644 --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -13906,7 +13906,7 @@ SYSCALL_DEFINE5(perf_event_open, if (err) return err; - if (!attr.exclude_kernel || + if (!attr.exclude_kernel || attr.text_poke || ((attr.sample_type & PERF_SAMPLE_CALLCHAIN) && !attr.exclude_callchain_kernel)) { err = perf_allow_kernel(); |
