[PATCH] bpftool: Fix out-of-bounds read in kprobe_multi link info dump
From: chenyuan_fl
Date: Sat Oct 10 2026 - 03:45:58 EST
From: Yuan Chen <chenyuan@xxxxxxxxxx>
show_kprobe_multi_{plain,json}() walk the sorted kallsyms array against
the sorted addr/cookie array with j as a cursor into the latter. The
loop terminating condition is checked after the cursor has already been
used to access the array:
if (j++ == info->kprobe_multi.count)
break;
After all count entries have been printed, j has been bumped to count,
but the loop keeps running and dereferences data[count] -- one element
past the end of the calloc(count, sizeof(*data)) allocation -- while
comparing every remaining kallsyms symbol. If the out-of-bounds value
happens to match a symbol address, a bogus entry with a garbage
addr/cookie pair is printed to boot.
Fix the off-by-one by advancing the cursor before the comparison, so the
loop terminates as soon as the last entry has been printed.
Verified with an ASAN build of bpftool against a live kprobe_multi link
of 3 symbols:
before: ERROR: AddressSanitizer: heap-buffer-overflow READ of size 8
at link.c:860 (show_kprobe_multi_plain) and link.c:352
(show_kprobe_multi_json), 0 bytes after the 48-byte
get_addr_cookie_array() allocation
after: clean output, no ASAN report
Fixes: edd7f49bb884 ("bpftool: Show kprobe_multi link info")
Signed-off-by: Yuan Chen <chenyuan@xxxxxxxxxx>
---
tools/bpf/bpftool/link.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/tools/bpf/bpftool/link.c b/tools/bpf/bpftool/link.c
index 088d1d206065..5cffa2d283b4 100644
--- a/tools/bpf/bpftool/link.c
+++ b/tools/bpf/bpftool/link.c
@@ -364,7 +364,7 @@ show_kprobe_multi_json(struct bpf_link_info *info, json_writer_t *wtr)
}
jsonw_uint_field(json_wtr, "cookie", data[j].cookie);
jsonw_end_object(json_wtr);
- if (j++ == info->kprobe_multi.count)
+ if (++j == info->kprobe_multi.count)
break;
}
jsonw_end_array(json_wtr);
@@ -867,7 +867,7 @@ static void show_kprobe_multi_plain(struct bpf_link_info *info)
else
printf(" ");
- if (j++ == info->kprobe_multi.count)
+ if (++j == info->kprobe_multi.count)
break;
}
error:
--
2.54.0