[PATCH v1 2/2] perf build-id: Ensure snprintf string is empty when size is 0
From: Ian Rogers
Date: Thu Sep 18 2025 - 13:24:21 EST
The string result of build_id__snprintf is unconditionally used in
places like dsos__fprintf_buildid_cb. If the build id has size 0 then
this creates a use of uninitialized memory. Add null termination for
the size 0 case.
A similar fix was written by Jiri Olsa in commit 6311951d4f8f ("perf
tools: Initialize output buffer in build_id__sprintf") but lost in the
transition to snprintf.
Fixes: fccaaf6fbbc5 ("perf build-id: Change sprintf functions to snprintf")
Signed-off-by: Ian Rogers <irogers@xxxxxxxxxx>
---
tools/perf/util/build-id.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/tools/perf/util/build-id.c b/tools/perf/util/build-id.c
index bf7f3268b9a2..35505a1ffd11 100644
--- a/tools/perf/util/build-id.c
+++ b/tools/perf/util/build-id.c
@@ -86,6 +86,13 @@ int build_id__snprintf(const struct build_id *build_id, char *bf, size_t bf_size
{
size_t offs = 0;
+ if (build_id->size == 0) {
+ /* Ensure bf is always \0 terminated. */
+ if (bf_size > 0)
+ bf[0] = '\0';
+ return 0;
+ }
+
for (size_t i = 0; i < build_id->size && offs < bf_size; ++i)
offs += snprintf(bf + offs, bf_size - offs, "%02x", build_id->data[i]);
--
2.51.0.470.ga7dc726c21-goog