[PATCH 06/15] perf/x86/intel: Limit PEBS counter iteration to valid array bounds
From: Dapeng Mi
Date: Mon Sep 28 2026 - 03:51:46 EST
__intel_pmu_handle_{,last_}pebs_record() iterate counter indexes up to
X86_PMC_IDX_MAX (64), while counts[] and *last[] are sized only for
INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS (48) entries.
If pebs_status were ever to contain bits above the highest valid PEBS
counter index, the loop could access those arrays out of bounds.
Although that should not happen in practice, limit the iteration bound
to INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS to match the array
sizes and keep the code consistent.
Fixes: 8807d922705f ("perf/x86/intel/ds: Factor out PEBS record processing code to functions")
Signed-off-by: Dapeng Mi <dapeng1.mi@xxxxxxxxxxxxxxx>
---
arch/x86/events/intel/ds.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/arch/x86/events/intel/ds.c b/arch/x86/events/intel/ds.c
index 0f24098587bf..f68391d60b2d 100644
--- a/arch/x86/events/intel/ds.c
+++ b/arch/x86/events/intel/ds.c
@@ -3239,7 +3239,8 @@ __intel_pmu_handle_pebs_record(struct pt_regs *iregs,
struct perf_event *event;
int bit;
- for_each_set_bit(bit, (unsigned long *)&pebs_status, X86_PMC_IDX_MAX) {
+ for_each_set_bit(bit, (unsigned long *)&pebs_status,
+ INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS) {
event = cpuc->events[bit];
if (WARN_ON_ONCE(!event) ||
@@ -3268,7 +3269,8 @@ __intel_pmu_handle_last_pebs_record(struct pt_regs *iregs,
bool handled = false;
int bit;
- for_each_set_bit(bit, (unsigned long *)&mask, X86_PMC_IDX_MAX) {
+ for_each_set_bit(bit, (unsigned long *)&mask,
+ INTEL_PMC_IDX_FIXED + MAX_FIXED_PEBS_EVENTS) {
if (!counts[bit])
continue;
--
2.34.1