+8
−7
Loading
Syzkaller reported a KASAN slab-out-of-bounds write in __bpf_get_stackid() when copying stack trace data. The issue occurs when the perf trace contains more stack entries than the stack map bucket can hold, leading to an out-of-bounds write in the bucket's data array. Fixes: ee2a0988 ("bpf: Adjust BPF stack helper functions to accommodate skip > 0") Reported-by:<syzbot+c9b724fbb41cf2538b7b@syzkaller.appspotmail.com> Signed-off-by:
Arnaud Lecomte <contact@arnaud-lcm.com> Signed-off-by:
Andrii Nakryiko <andrii@kernel.org> Acked-by:
Yonghong Song <yonghong.song@linux.dev> Acked-by:
Song Liu <song@kernel.org> Link: https://lore.kernel.org/bpf/20251025192941.1500-1-contact@arnaud-lcm.com Closes: https://syzkaller.appspot.com/bug?extid=c9b724fbb41cf2538b7b