Re: [PATCH] bpftool: Fix out-of-bounds read in kprobe_multi link info dump

From: Yafang Shao

Date: Sat Oct 10 2026 - 04:26:58 EST


On Sat, Oct 10, 2026 at 3:45 PM <chenyuan_fl@xxxxxxx> wrote:
>
> From: Yuan Chen <chenyuan@xxxxxxxxxx>
>
> show_kprobe_multi_{plain,json}() walk the sorted kallsyms array against
> the sorted addr/cookie array with j as a cursor into the latter. The
> loop terminating condition is checked after the cursor has already been
> used to access the array:
>
> if (j++ == info->kprobe_multi.count)
> break;
>
> After all count entries have been printed, j has been bumped to count,
> but the loop keeps running and dereferences data[count] -- one element
> past the end of the calloc(count, sizeof(*data)) allocation -- while
> comparing every remaining kallsyms symbol. If the out-of-bounds value
> happens to match a symbol address, a bogus entry with a garbage
> addr/cookie pair is printed to boot.
>
> Fix the off-by-one by advancing the cursor before the comparison, so the
> loop terminates as soon as the last entry has been printed.
>
> Verified with an ASAN build of bpftool against a live kprobe_multi link
> of 3 symbols:
>
> before: ERROR: AddressSanitizer: heap-buffer-overflow READ of size 8
> at link.c:860 (show_kprobe_multi_plain) and link.c:352
> (show_kprobe_multi_json), 0 bytes after the 48-byte
> get_addr_cookie_array() allocation
> after: clean output, no ASAN report
>
> Fixes: edd7f49bb884 ("bpftool: Show kprobe_multi link info")
> Signed-off-by: Yuan Chen <chenyuan@xxxxxxxxxx>

Nice catch!

Acked-by: Yafang Shao <laoar.shao@xxxxxxxxx>

> ---
> tools/bpf/bpftool/link.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/tools/bpf/bpftool/link.c b/tools/bpf/bpftool/link.c
> index 088d1d206065..5cffa2d283b4 100644
> --- a/tools/bpf/bpftool/link.c
> +++ b/tools/bpf/bpftool/link.c
> @@ -364,7 +364,7 @@ show_kprobe_multi_json(struct bpf_link_info *info, json_writer_t *wtr)
> }
> jsonw_uint_field(json_wtr, "cookie", data[j].cookie);
> jsonw_end_object(json_wtr);
> - if (j++ == info->kprobe_multi.count)
> + if (++j == info->kprobe_multi.count)
> break;
> }
> jsonw_end_array(json_wtr);
> @@ -867,7 +867,7 @@ static void show_kprobe_multi_plain(struct bpf_link_info *info)
> else
> printf(" ");
>
> - if (j++ == info->kprobe_multi.count)
> + if (++j == info->kprobe_multi.count)
> break;
> }
> error:
> --
> 2.54.0
>


--
Regards
Yafang