[PATCH 2/4] tracing/probes: Prevent out-of-bounds write in __trace_probe_log_err()

From: Masami Hiramatsu (Google)

Date: Mon Jul 20 2026 - 06:23:58 EST


From: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>

If trace_probe_log.argc is 0 in __trace_probe_log_err(), the loop
constructing the command string will not execute and p will remain equal to
command. Writing to *(p - 1) will cause an out-of-bounds access before
command. This should not happen, but better to be treated.

Reject if trace_probe_log.argc is 0.

Fixes: ab105a4fb894 ("tracing: Use tracing error_log with probe events")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
---
kernel/trace/trace_probe.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/trace/trace_probe.c b/kernel/trace/trace_probe.c
index 95e3d072321f..49daa3cc2a45 100644
--- a/kernel/trace/trace_probe.c
+++ b/kernel/trace/trace_probe.c
@@ -188,7 +188,7 @@ void __trace_probe_log_err(int offset, int err_type)

lockdep_assert_held(&dyn_event_ops_mutex);

- if (!trace_probe_log.argv)
+ if (!trace_probe_log.argv || !trace_probe_log.argc)
return;

/* Recalculate the length and allocate buffer */