Thread (9 messages) flat view 9 messages, 5 authors, 27d ago

Re: [PATCH] uprobes: Fix NULL pointer dereference in hprobe_expire()

From: Andrii Nakryiko <hidden>
Date: 2026-07-29 19:31:24
Also in: linux-perf-users, lkml, stable

On Wed, Jul 29, 2026 at 9:02 AM Oleg Nesterov [off-list ref] wrote:
On 07/29, Breno Leitao wrote:
quoted
--- a/kernel/events/uprobes.c
+++ b/kernel/events/uprobes.c
@@ -832,7 +832,7 @@ static struct uprobe *hprobe_expire(struct hprobe *hprobe, bool get)
              if (try_cmpxchg(&hprobe->state, &hstate, uprobe ? HPROBE_STABLE : HPROBE_GONE)) {
                      /* We won the race, we are the ones to unlock SRCU */
                      __srcu_read_unlock(&uretprobes_srcu, hprobe->srcu_idx);
-                     return get ? get_uprobe(uprobe) : uprobe;
+                     return get && uprobe ? get_uprobe(uprobe) : uprobe;
Well, looks "obviously correct". At least the current code is obviously
wrong, it even checks uprobe != NULL 3 lines above.

Andrii ?
Yes, indeed, I'm more surprised this didn't come up much earlier
(probably it's rare enough to have uretprobe with refcnt at zero
during fork). The fix looks good, thanks!

Acked-by: Andrii Nakryiko <andrii@kernel.org>
Acked-by: Oleg Nesterov <oleg@redhat.com>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help