Commit 7a39c732a22e for kernel

commit 7a39c732a22ec4a369af9e19fbe3d666ec83eec4
Author: Leon Hwang <leon.hwang@linux.dev>
Date:   Wed Sep 30 13:36:18 2026 +0800

    kprobes: Skip disarmed probes when checking optkprobe overlap

    On x86, an optkprobe at A replaces five bytes with a jump. If a disabled
    probe B is at A+2, get_optimized_kprobe() stops at B when arming a new
    probe C at A+4. It leaves A optimized:

                  A    A+1  A+2  A+3  A+4
      A's jump  | e9 | d0 | d1 | d2 | d3 |
      after C   | e9 | d0 | d1 | d2 | cc |

    The INT3 for C overwrites the last byte of A's jump displacement, so
    execution can jump to the wrong address. B can have prepared optinsns
    while disarmed, but has no jump to unoptimize.

    Continue past disarmed and unprepared probes to find the active optimized
    probe before arming a probe in its jump.

    Link: https://lore.kernel.org/all/20260930053618.104498-1-leon.hwang@linux.dev/

    Fixes: afd66255b9a4 ("kprobes: Introduce kprobes jump optimization")
    Cc: stable@vger.kernel.org
    Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
    Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>

diff --git a/kernel/kprobes.c b/kernel/kprobes.c
index 4edd8ca5c657..e787e4948c8b 100644
--- a/kernel/kprobes.c
+++ b/kernel/kprobes.c
@@ -496,14 +496,16 @@ static bool kprobe_queued(struct kprobe *p)
 static struct kprobe *get_optimized_kprobe(kprobe_opcode_t *addr)
 {
 	int i;
-	struct kprobe *p = NULL;
+	struct kprobe *p;
 	struct optimized_kprobe *op;

 	/* Don't check i == 0, since that is a breakpoint case. */
-	for (i = 1; !p && i < MAX_OPTIMIZED_LENGTH / sizeof(kprobe_opcode_t); i++)
+	for (i = 1; i < MAX_OPTIMIZED_LENGTH / sizeof(kprobe_opcode_t); i++) {
 		p = get_kprobe(addr - i);
+		/* A disabled probe can have prepared, but inactive, optinsns. */
+		if (!p || !kprobe_optready(p) || kprobe_disarmed(p))
+			continue;

-	if (p && kprobe_optready(p)) {
 		op = container_of(p, struct optimized_kprobe, kp);
 		if (arch_within_optimized_kprobe(op, addr))
 			return p;