[PATCH 5.15.y] kprobes: Protect kprobe_blacklist with RCU
flat view
DORMANTno replies
From: Sasha Levin <sashal@kernel.org>
Date: 2026-09-10 15:37:53
Subsystem:
kprobes, the rest · Maintainers:
Naveen N Rao, "David S. Miller", Masami Hiramatsu, Linus Torvalds
From: "Masami Hiramatsu (Google)" <mhiramat@kernel.org> [ Upstream commit 0c4256196b3a105307e2235fbfd85e768bbcdd0f ] __within_kprobe_blacklist() traverses kprobe_blacklist without holding kprobe_mutex. When a module is unloaded, kprobe_remove_area_blacklist() removes blacklist entries and immediately frees them with kfree(). A concurrent call to within_kprobe_blacklist() can therefore dereference freed memory. Furthermore, within_kprobe_blacklist() can be called in atomic or non-preemptible contexts where the sleeping kprobe_mutex cannot be taken. Protect kprobe_blacklist with RCU. Use guard(rcu)() and list_for_each_entry_rcu() for traversal, list_add_tail_rcu() for insertions, list_del_rcu() for deletions, and kfree_rcu() to reclaim entries safely after a grace period. Link: https://lore.kernel.org/all/178810004323.64882.16493230858653316962.stgit@devnote2/ (local) Fixes: 376e242429bf ("kprobes: Introduce NOKPROBE_SYMBOL() macro to maintain kprobes blacklist") Cc: stable@vger.kernel.org Reported-by: Sashiko <sashiko-bot@kernel.org> Closes: https://lore.kernel.org/all/20260807155802.F06041F000E9@smtp.kernel.org/ (local) Assisted-by: Antigravity:gemini-3.7-flash Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org> [ Replaced guard(rcu)() with explicit rcu_read_lock()/rcu_read_unlock() to avoid declaration-after-statement warnings. ] Signed-off-by: Sasha Levin <sashal@kernel.org> --- include/linux/kprobes.h | 1 + kernel/kprobes.c | 19 ++++++++++++++----- 2 files changed, 15 insertions(+), 5 deletions(-)
diff --git a/include/linux/kprobes.h b/include/linux/kprobes.h
index 24b0eaa5de307..e5262feff8267 100644
--- a/include/linux/kprobes.h
+++ b/include/linux/kprobes.h@@ -177,6 +177,7 @@ struct kprobe_blacklist_entry { struct list_head list; unsigned long start_addr; unsigned long end_addr; + struct rcu_head rcu; }; #ifdef CONFIG_KPROBES
diff --git a/kernel/kprobes.c b/kernel/kprobes.c
index 0d463859ad329..69d166f42d04a 100644
--- a/kernel/kprobes.c
+++ b/kernel/kprobes.c@@ -1427,11 +1427,20 @@ static bool __within_kprobe_blacklist(unsigned long addr) /* * If there exists a kprobe_blacklist, verify and * fail any probe registration in the prohibited area + * Note: this can return true during transition period where + * (start_addr, end_addr) in the black list is shrinking + * but old entry has not been removed yet. This is acceptable + * because the worst case is that we reject more probes than + * we should. */ - list_for_each_entry(ent, &kprobe_blacklist, list) { - if (addr >= ent->start_addr && addr < ent->end_addr) + rcu_read_lock(); + list_for_each_entry_rcu(ent, &kprobe_blacklist, list) { + if (addr >= ent->start_addr && addr < ent->end_addr) { + rcu_read_unlock(); return true; + } } + rcu_read_unlock(); return false; }
@@ -2258,7 +2267,7 @@ int kprobe_add_ksym_blacklist(unsigned long entry) ent->start_addr = entry; ent->end_addr = entry + size; INIT_LIST_HEAD(&ent->list); - list_add_tail(&ent->list, &kprobe_blacklist); + list_add_tail_rcu(&ent->list, &kprobe_blacklist); return (int)size; }
@@ -2287,8 +2296,8 @@ static void kprobe_remove_area_blacklist(unsigned long start, unsigned long end) list_for_each_entry_safe(ent, n, &kprobe_blacklist, list) { if (ent->start_addr < start || ent->start_addr >= end) continue; - list_del(&ent->list); - kfree(ent); + list_del_rcu(&ent->list); + kfree_rcu(ent, rcu); } }
--
2.53.0