[PATCH] fprobe: Protect fprobe_return() with guard(rcu)()

From: Masami Hiramatsu (Google)

Date: Sun Sep 27 2026 - 20:36:03 EST


Hi,

Here is a bugfix (possible UAF) for fprobe found by Sashiko[1].
[1] https://sashiko.dev/#/bug/linux-e46bcd68-4a56-4f19-a255-e3772980e5e3

I think this fix is a short-term fix to make it safer. Eventually
I would like to replace all guard(rcu)() from fprobe with
preempt_disable_notrace(), because currently it introduces unneeded
overhead to fprobe.

- Introduce new call_rcu_tasks_rude() for async call.
- Add special non-preempt mode flag to rhashtable, which
uses call_rcu_tasks_rude() instead of call_rcu()
- Switching to use synchronize_rcu_tasks_rude() for unregistering.
- Replace call_rcu() with call_rcu_tasks_rude() in BPF.

But this is heavy depends on Tasks RCU, so I would like to check
with the RCU maintainers whether this idea aligns with the concept
behind Tasks RCU updates.

Thanks,

---

Masami Hiramatsu (Google) (1):
fprobe: Protect fprobe_return() with guard(rcu)()


kernel/trace/fprobe.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)

--
Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>