ACK: [SRU][N][PATCH 0/1] CVE-2025-38563

Andrei Gherzan andrei.gherzan at canonical.com
Wed Sep 16 13:45:02 UTC 2026


On 26/09/11 06:37AM, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2025-38563
> 
> [ Impact ]
> 
> In the Linux kernel, the following vulnerability has been resolved:
> 
> perf/core: Prevent VMA split of buffer mappings
> 
> The perf mmap code is careful about mmap()'ing the user page with the
> ringbuffer and additionally the auxiliary buffer, when the event supports it.
> Once the first mapping is established, subsequent mapping have to use the same
> offset and the same size in both cases. The reference counting for the
> ringbuffer and the auxiliary buffer depends on this being correct.
> 
> Though perf does not prevent that a related mapping is split via mmap(2),
> munmap(2) or mremap(2). A split of a VMA results in perf_mmap_open() calls,
> which take reference counts, but then the subsequent perf_mmap_close() calls
> are not longer fulfilling the offset and size checks. This leads to reference
> count leaks.
> 
> As perf already has the requirement for subsequent mappings to match the
> initial mapping, the obvious consequence is that VMA splits, caused by resizing
> of a mapping or partial unmapping, have to be prevented.
> 
> Implement the vm_operations_struct::may_split() callback and return
> unconditionally -EINVAL.
> 
> That ensures that the mapping offsets and sizes cannot be changed after the
> fact. Remapping to a different fixed address with the same size is still
> possible as it takes the references for the new mapping and drops those of the
> old mapping.
> 
> [ Fix ]
> 
> noble/linux: backported from b024d7b56c77
> 
> [ Test Plan ]
> 
> Build and boot tested.
> 
> [ Where Problems Could Occur ]
> 
> The fix touches the perf subsystem's mmap path by adding a may_split()
> callback that unconditionally rejects VMA splits of perf buffer mappings. A
> bad fix could affect any workload that uses perf ring buffer or AUX area
> mappings, such as profiling and tracing tools (perf, PMU-based sampling, and
> Intel PT or similar AUX-based tracing) that call munmap(2) or mremap(2) on
> parts of a perf mapping and now receive -EINVAL. Systems that do not run perf
> profiling or tracing are not affected, and applications that map and unmap
> perf buffers as whole units continue to work unchanged.
> 
> [ Other Info ]
> 
> Kybele flow-v11-25-ga27c0fa6. Reference: f621fb01/v1

Acked-by: Andrei Gherzan <andrei.gherzan at canonical.com>

-- 
Andrei Gherzan
gpg: rsa4096/D4D94F67AD0E9640
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260916/1d5e0166/attachment.sig>


More information about the kernel-team mailing list