Re: [PATCH] uprobes: Fix NULL pointer dereference in hprobe_expire()
From: Oleg Nesterov
Date: Wed Jul 29 2026 - 12:24:55 EST
On 07/29, Breno Leitao wrote:
>
> --- a/kernel/events/uprobes.c
> +++ b/kernel/events/uprobes.c
> @@ -832,7 +832,7 @@ static struct uprobe *hprobe_expire(struct hprobe *hprobe, bool get)
> if (try_cmpxchg(&hprobe->state, &hstate, uprobe ? HPROBE_STABLE : HPROBE_GONE)) {
> /* We won the race, we are the ones to unlock SRCU */
> __srcu_read_unlock(&uretprobes_srcu, hprobe->srcu_idx);
> - return get ? get_uprobe(uprobe) : uprobe;
> + return get && uprobe ? get_uprobe(uprobe) : uprobe;
Well, looks "obviously correct". At least the current code is obviously
wrong, it even checks uprobe != NULL 3 lines above.
Andrii ?
Acked-by: Oleg Nesterov <oleg@xxxxxxxxxx>