ACK: [SRU][N][PATCH 0/1] CVE-2025-38563

Edoardo Canepa edoardo.canepa at canonical.com
Wed Sep 16 08:01:20 UTC 2026


Acked-by: Edoardo Canepa <edoardo.canepa at canonical.com>

On 9/11/26 08:37, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2025-38563
>
> [ Impact ]
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> perf/core: Prevent VMA split of buffer mappings
>
> The perf mmap code is careful about mmap()'ing the user page with the
> ringbuffer and additionally the auxiliary buffer, when the event supports it.
> Once the first mapping is established, subsequent mapping have to use the same
> offset and the same size in both cases. The reference counting for the
> ringbuffer and the auxiliary buffer depends on this being correct.
>
> Though perf does not prevent that a related mapping is split via mmap(2),
> munmap(2) or mremap(2). A split of a VMA results in perf_mmap_open() calls,
> which take reference counts, but then the subsequent perf_mmap_close() calls
> are not longer fulfilling the offset and size checks. This leads to reference
> count leaks.
>
> As perf already has the requirement for subsequent mappings to match the
> initial mapping, the obvious consequence is that VMA splits, caused by resizing
> of a mapping or partial unmapping, have to be prevented.
>
> Implement the vm_operations_struct::may_split() callback and return
> unconditionally -EINVAL.
>
> That ensures that the mapping offsets and sizes cannot be changed after the
> fact. Remapping to a different fixed address with the same size is still
> possible as it takes the references for the new mapping and drops those of the
> old mapping.
>
> [ Fix ]
>
> noble/linux: backported from b024d7b56c77
>
> [ Test Plan ]
>
> Build and boot tested.
>
> [ Where Problems Could Occur ]
>
> The fix touches the perf subsystem's mmap path by adding a may_split()
> callback that unconditionally rejects VMA splits of perf buffer mappings. A
> bad fix could affect any workload that uses perf ring buffer or AUX area
> mappings, such as profiling and tracing tools (perf, PMU-based sampling, and
> Intel PT or similar AUX-based tracing) that call munmap(2) or mremap(2) on
> parts of a perf mapping and now receive -EINVAL. Systems that do not run perf
> profiling or tracing are not affected, and applications that map and unmap
> perf buffers as whole units continue to work unchanged.
>
> [ Other Info ]
>
> Kybele flow-v11-25-ga27c0fa6. Reference: f621fb01/v1
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260916/6d12ad60/attachment.sig>


More information about the kernel-team mailing list