From f613a6d694aa499edb2a291ab2c2d906619585f2 Mon Sep 17 00:00:00 2001 From: Arnaldo Carvalho de Melo Date: Fri, 10 Apr 2026 19:08:59 -0300 Subject: perf header: Sanity check HEADER_PMU_MAPPINGS Add upper bound check on pmu_num in process_pmu_mappings() to harden against malformed perf.data files (max 4096). Cc: Ian Rogers Assisted-by: Claude Code:claude-opus-4-6 Signed-off-by: Arnaldo Carvalho de Melo Signed-off-by: Namhyung Kim --- tools/perf/util/header.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/tools/perf/util/header.c b/tools/perf/util/header.c index 2eb909672f82..77035d9b138c 100644 --- a/tools/perf/util/header.c +++ b/tools/perf/util/header.c @@ -64,6 +64,7 @@ #endif #define MAX_NUMA_NODES 4096 +#define MAX_PMU_MAPPINGS 4096 #define MAX_SCHED_DOMAINS 64 /* @@ -3069,6 +3070,18 @@ static int process_pmu_mappings(struct feat_fd *ff, void *data __maybe_unused) return 0; } + if (pmu_num > MAX_PMU_MAPPINGS) { + pr_err("Invalid HEADER_PMU_MAPPINGS: pmu_num (%u) > %u\n", + pmu_num, MAX_PMU_MAPPINGS); + return -1; + } + + if (ff->size < sizeof(u32) + pmu_num * 2 * sizeof(u32)) { + pr_err("Invalid HEADER_PMU_MAPPINGS: section too small (%zu) for %u PMUs\n", + ff->size, pmu_num); + return -1; + } + env->nr_pmu_mappings = pmu_num; if (strbuf_init(&sb, 128) < 0) return -1; -- cgit v1.2.3