Re: [PATCH] s390/kprobes: Prevent kprobes on instructions with exception table entry
From: Heiko Carstens
Date: Thu Sep 24 2026 - 11:43:15 EST
On Thu, Sep 24, 2026 at 01:57:24PM +0200, Heiko Carstens wrote:
> The mvcos exception handler ex_handler_ua_mvcos() decodes the faulting
> instruction, assuming it is an mvcos instruction. In case the instruction
> is kprobed the decoded instruction is a breakpoint instruction instead,
> which leads to incorrect instruction decoding and potential register
> corruption.
>
> Fix this by simply preventing to set a kprobe on such instructions,
> similar like arm64 is doing it.
>
> Fixes: c488f5187a24 ("s390/uaccess: Shorten raw_copy_from_user() / raw_copy_to_user() inline assemblies")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Heiko Carstens <hca@xxxxxxxxxxxxx>
> ---
> arch/s390/kernel/kprobes.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/arch/s390/kernel/kprobes.c b/arch/s390/kernel/kprobes.c
> index c450120b4474..e806b124e4ba 100644
> --- a/arch/s390/kernel/kprobes.c
> +++ b/arch/s390/kernel/kprobes.c
> @@ -85,6 +85,9 @@ static bool can_probe(unsigned long paddr)
> if (!kallsyms_lookup_size_offset(paddr, NULL, &offset))
> return false;
>
> + if (s390_search_extables(paddr))
> + return false;
> +
> /* Decode instructions */
FWIW, I believe x86 has a similar problem since it tries to decode the mov
instruction of load_unaligned_zeropad() in ex_handler_zeropad() which was
introduced with [1]. If a kprobe is placed there instruction decoding will
fail.
As far as I can tell there is nothing that prevents that a kprobe is placed
there.
[1] c4e34dd99f2e ("x86: simplify load_unaligned_zeropad() implementation")