perf/core: Bail out early if the request AUX area is out of bound
Published May 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.25%
Description
When perf-record with a large AUX area, e.g 4GB, it fails with:
#perf record -C 0 -m ,4G -e arm_spe_0// -- sleep 1 failed to mmap with 12 (Cannot allocate memory)
and it reveals a WARNING with __alloc_pages():
------------[ cut here ]------------ WARNING: CPU: 44 PID: 17573 at mm/page_alloc.c:5568 __alloc_pages+0x1ec/0x248 Call trace: __alloc_pages+0x1ec/0x248 __kmalloc_large_node+0xc0/0x1f8 __kmalloc_node+0x134/0x1e8 rb_alloc_aux+0xe0/0x298 perf_mmap+0x440/0x660 mmap_region+0x308/0x8a8 do_mmap+0x3c0/0x528 vm_mmap_pgoff+0xf4/0x1b8 ksys_mmap_pgoff+0x18c/0x218 __arm64_sys_mmap+0x38/0x58 invoke_syscall+0x50/0x128 el0_svc_common.constprop.0+0x58/0x188 do_el0_svc+0x34/0x50 el0_svc+0x34/0x108 el0t_64_sync_handler+0xb8/0xc0 el0t_64_sync+0x1a4/0x1a8
'rb->aux_pages' allocated by kcalloc() is a pointer array which is used to maintains AUX trace pages. The allocated page for this array is physically contiguous (and virtually contiguous) with an order of 0..MAX_ORDER. If the size of pointer array crosses the limitation set by MAX_ORDER, it reveals a WARNING.
So bail out early with -ENOMEM if the request AUX area is out of bound, e.g.:
#perf record -C 0 -m ,4G -e arm_spe_0// -- sleep 1 failed to mmap with 12 (Cannot allocate memory)
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 4.1
Unaffected
- ≥ 0, < 4.1
- ≥ 4.19.300, ≤ 4.19.*
- ≥ 5.10.202, ≤ 5.10.*
- ≥ 5.15.140, ≤ 5.15.*
- ≥ 5.4.262, ≤ 5.4.*
- ≥ 6.1.64, ≤ 6.1.*
- ≥ 6.5.13, ≤ 6.5.*
- ≥ 6.6.3, ≤ 6.6.*
- 6.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- < 4.19.300
- ≥ 4.20 · < 5.4.262
- ≥ 5.5 · < 5.10.202
- ≥ 5.11 · < 5.15.140
- ≥ 5.16 · < 6.1.64
- ≥ 6.2 · < 6.5.13
- ≥ 6.6 · < 6.6.3
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.8.1.el8_10
Fixed · RHSA-2024:4211
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.8.1.rt7.349.el8_10
Fixed · RHSA-2024:4352
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.79.1.el9_4
Fixed · RHSA-2025:11810
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.8.1.el8_10 | Fixed | RHSA-2024:4211 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.8.1.rt7.349.el8_10 | Fixed | RHSA-2024:4352 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.79.1.el9_4 | Fixed | RHSA-2025:11810 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-52835 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282735 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59549 Advisory
- https://git.kernel.org/stable/c/1a2a4202c60fcdffbf04f259002ce9bff39edece Patch
- https://git.kernel.org/stable/c/2424410f94a94d91230ced094062d859714c984a Patch
- https://git.kernel.org/stable/c/2e905e608e38cf7f8dcddcf8a6036e91a78444cb Patch
- https://git.kernel.org/stable/c/54aee5f15b83437f23b2b2469bcf21bdd9823916 Patch
- https://git.kernel.org/stable/c/788c0b3442ead737008934947730a6d1ff703734 Patch
- https://git.kernel.org/stable/c/8c504f615d7ed60ae035c51d0c789137ced6797f Patch
- https://git.kernel.org/stable/c/9ce4e87a8efd37c85766ec08b15e885cab08553a Patch
- https://git.kernel.org/stable/c/fd0df3f8719201dbe61a4d39083d5aecd705399a Patch
- https://lore.kernel.org/linux-cve-announce/2024052109-CVE-2023-52835-80ee@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-52835
- https://www.cve.org/CVERecord?id=CVE-2023-52835
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data