[PATCH 7/9] modpost: fix pointer arithmetic on NULL in parse_source_files()

From: lzhan011

Date: Mon Oct 05 2026 - 06:43:17 EST


From: lzhan011 <zhangleizhen645@xxxxxxxxx>

parse_source_files() checks whether a dependency is in the same directory
as the object file with

(strstr(line, dir) + strlen(dir) - 1) == strrchr(line, '/')

When the dependency is not below dir, strstr() returns NULL and the
pointer arithmetic on NULL is undefined behaviour. This happens for
every module with dependencies outside its own directory, and UBSan
reports:

scripts/mod/sumversion.c: runtime error: applying non-zero offset
to null pointer

Check the result of strstr() before using it.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Claude:claude-opus-5-5 UBSan
Signed-off-by: lzhan011 <zhangleizhen645@xxxxxxxxx>
---
scripts/mod/sumversion.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/scripts/mod/sumversion.c b/scripts/mod/sumversion.c
index 3dd28b4d0..4c59e7cfb 100644
--- a/scripts/mod/sumversion.c
+++ b/scripts/mod/sumversion.c
@@ -364,7 +364,8 @@ static int parse_source_files(const char *objfile, struct md4_ctx *md)
}

/* Check if this file is in same dir as objfile */
- if ((strstr(line, dir)+strlen(dir)-1) == strrchr(line, '/')) {
+ p = strstr(line, dir);
+ if (p && p + dirlen - 1 == strrchr(line, '/')) {
if (!parse_file(line, md)) {
warn("could not open %s: %s\n",
line, strerror(errno));
--
2.34.1