[PATCH] kallsyms: Always null-initialize modbuildid
From: Maurice Hieronymus
Date: Mon Dec 08 2025 - 16:47:33 EST
modbuildid is never set when kallsyms_lookup_buildid is returning via
successful ftrace_mod_address_lookup.
This leads to an uninitialized pointer dereference on x86 when
CONFIG_STACKTRACE_BUILD_ID=y inside __sprint_symbol.
Prevent this by always initializing modbuildid and modname with NULL.
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=220717
Signed-off-by: Maurice Hieronymus <mhi@xxxxxxxxxxx>
---
kernel/kallsyms.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/kernel/kallsyms.c b/kernel/kallsyms.c
index 049e296f586c..f83ee976e7d5 100644
--- a/kernel/kallsyms.c
+++ b/kernel/kallsyms.c
@@ -358,6 +358,12 @@ static int kallsyms_lookup_buildid(unsigned long addr,
namebuf[KSYM_NAME_LEN - 1] = 0;
namebuf[0] = 0;
+ /* Some code paths leave modname/modbuildid uninitialized; set to NULL */
+ if (modname)
+ *modname = NULL;
+ if (modbuildid)
+ *modbuildid = NULL;
+
if (is_ksym_addr(addr)) {
unsigned long pos;
@@ -365,10 +371,6 @@ static int kallsyms_lookup_buildid(unsigned long addr,
/* Grab name */
kallsyms_expand_symbol(get_symbol_offset(pos),
namebuf, KSYM_NAME_LEN);
- if (modname)
- *modname = NULL;
- if (modbuildid)
- *modbuildid = NULL;
return strlen(namebuf);
}
base-commit: c2f2b01b74be8b40a2173372bcd770723f87e7b2
--
2.50.1