Re: [PATCH] perf powerpc-vpadtl: Fix off-by-one in auxtrace_info minimum size check

From: Adrian Hunter

Date: Mon Aug 24 2026 - 03:48:31 EST


On 24/08/2026 05:55, Wang Yan wrote:
> min_sz is set to sizeof(u64) * POWERPC_VPADTL_TYPE, but the code reads
> auxtrace_info->priv[POWERPC_VPADTL_TYPE], which needs at least
> POWERPC_VPADTL_TYPE + 1 elements. POWERPC_VPADTL_TYPE is the first
> enumerator of the priv index enum (0), so min_sz evaluates to 0 and the
> check validates only the perf_record_auxtrace_info header itself. A
> PERF_RECORD_AUXTRACE_INFO event carrying a zero-length priv array then
> passes the size check, and the subsequent priv[POWERPC_VPADTL_TYPE]
> read runs one u64 past the validated region.
>
> This is the same off-by-one fixed for Intel PT by commit c4362d5e1a5e
> ("perf intel-pt: Fix off-by-one in auxtrace_info minimum size check")
> and for Intel BTS by commit b9fb8225951c ("perf intel-bts: Fix off-by-one
> in auxtrace_info minimum size check").
>
> Use sizeof(u64) * (POWERPC_VPADTL_TYPE + 1) so the highest accessed
> priv index is covered by the minimum-size validation.
>
> Fixes: c4bbd4ec2e50 ("perf powerpc: Process auxtrace events and display in 'perf report -D'")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Wang Yan <wangyan01@xxxxxxxxxx>

Reviewed-by: Adrian Hunter <adrian.hunter@xxxxxxxxx>

> ---
> tools/perf/util/powerpc-vpadtl.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tools/perf/util/powerpc-vpadtl.c b/tools/perf/util/powerpc-vpadtl.c
> index 710f3093f3f9..c15636eef34b 100644
> --- a/tools/perf/util/powerpc-vpadtl.c
> +++ b/tools/perf/util/powerpc-vpadtl.c
> @@ -683,7 +683,7 @@ int powerpc_vpadtl_process_auxtrace_info(union perf_event *event,
> struct perf_session *session)
> {
> struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
> - size_t min_sz = sizeof(u64) * POWERPC_VPADTL_TYPE;
> + size_t min_sz = sizeof(u64) * (POWERPC_VPADTL_TYPE + 1);
> struct powerpc_vpadtl *vpa;
> int err;
>