diff options
| author | Zhengchuan Liang <zcliangcn@gmail.com> | 2026-09-28 10:59:35 -0700 |
|---|---|---|
| committer | Peter Zijlstra <peterz@infradead.org> | 2026-10-01 14:02:06 +0200 |
| commit | 357e8a77a501d96c9517f01f4a211eed5e9c9184 (patch) | |
| tree | bbdffc21a20e1ec35170513edb5de6df22101985 /scripts/gcc-plugins | |
| parent | b9d1fdc6f4ac1b6e49f9deafaf137da1407d9af1 (diff) | |
| download | linux-stable-357e8a77a501d96c9517f01f4a211eed5e9c9184.tar.gz linux-stable-357e8a77a501d96c9517f01f4a211eed5e9c9184.zip | |
perf: Require kernel access for text poke events
Perf events with exclude_kernel=1 can be opened without kernel perf
access. However, exclude_kernel does not suppress text-poke sideband
records. Every PERF_RECORD_TEXT_POKE is marked PERF_RECORD_MISC_KERNEL
and contains a raw kernel instruction address.
An unprivileged task can therefore open and mmap a task-local software
event with text_poke=1. Both opening a count-only tracepoint event and
configuring UDP GRO for ESP-in-UDP cause updates to inline static calls;
the observer receives the relocated addresses of the modified instructions.
For a known kernel image, any such address reveals the runtime kernel
text base despite KASLR.
Call perf_allow_kernel() whenever attr.text_poke is set, regardless of
exclude_kernel. Events that neither monitor kernel execution nor request
text-poke records retain their existing permissions.
Fixes: e17d43b93e54 ("perf: Add perf text poke event")
Assisted-by: LLM
Signed-off-by: Zhengchuan Liang <zcliangcn@gmail.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/99131354c41e23188f778b92f90363775b482395.1790573390.git.zcliangcn@gmail.com
Diffstat (limited to 'scripts/gcc-plugins')
0 files changed, 0 insertions, 0 deletions
