CVE-2024-53065: mm/slab: fix warning caused by duplicate kmem_cache creation in kmem_buckets_create
In the Linux kernel, the following vulnerability has been resolved:
mm/slab: fix warning caused by duplicate kmemcache creation in kmembucketscreate
Commit b035f5a6d852 ("mm: slab: reduce the kmalloc() minimum alignment if DMA bouncing possible") reduced ARCHKMALLOCMINALIGN to 8 on arm64. However, with KASANHWTAGS enabled, archslabminalign() becomes 16. This causes kmalloccaches[][8] to be aliased to kmalloccaches[][16], resulting in kmembucketscreate() attempting to create a kmemcache for size 16 twice. This duplication triggers warnings on boot:
[ 2.325108] ------------[ cut here ]------------ [ 2.325135] kmemcache of name 'memdupuser-16' already exists [ 2.325783] WARNING: CPU: 0 PID: 1 at mm/slabcommon.c:107 kmemcachecreateargs+0xb8/0x3b0 [ 2.327957] Modules linked in: [ 2.328550] CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-rc5mm-unstable-arm64+ #12 [ 2.328683] Hardware name: QEMU QEMU Virtual Machine, BIOS 2024.02-2 03/11/2024 [ 2.328790] pstate: 61000009 (nZCv daif -PAN -UAO -TCO +DIT -SSBS BTYPE=--) [ 2.328911] pc : kmemcachecreateargs+0xb8/0x3b0 [ 2.328930] lr : kmemcachecreateargs+0xb8/0x3b0 [ 2.328942] sp : ffff800083d6fc50 [ 2.328961] x29: ffff800083d6fc50 x28: f2ff0000c1674410 x27: ffff8000820b0598 [ 2.329061] x26: 000000007fffffff x25: 0000000000000010 x24: 0000000000002000 [ 2.329101] x23: ffff800083d6fce8 x22: ffff8000832222e8 x21: ffff800083222388 [ 2.329118] x20: f2ff0000c1674410 x19: f5ff0000c16364c0 x18: ffff800083d80030 [ 2.329135] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000 [ 2.329152] x14: 0000000000000000 x13: 0a73747369786520 x12: 79646165726c6120 [ 2.329169] x11: 656820747563205b x10: 2d2d2d2d2d2d2d2d x9 : 0000000000000000 [ 2.329194] x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 [ 2.329210] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 [ 2.329226] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 [ 2.329291] Call trace: [ 2.329407] kmemcachecreateargs+0xb8/0x3b0 [ 2.329499] kmembucketscreate+0xfc/0x320 [ 2.329526] inituserbuckets+0x34/0x78 [ 2.329540] dooneinitcall+0x64/0x3c8 [ 2.329550] kernelinitfreeable+0x26c/0x578 [ 2.329562] kernelinit+0x3c/0x258 [ 2.329574] retfromfork+0x10/0x20 [ 2.329698] ---[ end trace 0000000000000000 ]---
[ 2.403704] ------------[ cut here ]------------ [ 2.404716] kmemcache of name 'msgmsg-16' already exists [ 2.404801] WARNING: CPU: 2 PID: 1 at mm/slabcommon.c:107 kmemcachecreateargs+0xb8/0x3b0 [ 2.404842] Modules linked in: [ 2.404971] CPU: 2 UID: 0 PID: 1 Comm: swapper/0 Tainted: G W 6.12.0-rc5mm-unstable-arm64+ #12 [ 2.405026] Tainted: [W]=WARN [ 2.405043] Hardware name: QEMU QEMU Virtual Machine, BIOS 2024.02-2 03/11/2024 [ 2.405057] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 2.405079] pc : kmemcachecreateargs+0xb8/0x3b0 [ 2.405100] lr : kmemcachecreateargs+0xb8/0x3b0 [ 2.405111] sp : ffff800083d6fc50 [ 2.405115] x29: ffff800083d6fc50 x28: fbff0000c1674410 x27: ffff8000820b0598 [ 2.405135] x26: 000000000000ffd0 x25: 0000000000000010 x24: 0000000000006000 [ 2.405153] x23: ffff800083d6fce8 x22: ffff8000832222e8 x21: ffff800083222388 [ 2.405169] x20: fbff0000c1674410 x19: fdff0000c163d6c0 x18: ffff800083d80030 [ 2.405185] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000 [ 2.405201] x14: 0000000000000000 x13: 0a73747369786520 x12: 79646165726c6120 [ 2.405217] x11: 656820747563205b x10: 2d2d2d2d2d2d2d2d x9 : 0000000000000000 [ 2.405233] x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000 [ 2.405248] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 [ 2.405271] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000 [ 2.405287] Call trace: [ 2 ---truncated---
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53065?
CVE-2024-53065 is classified as a low severity vulnerability.
How do I fix CVE-2024-53065?
To fix CVE-2024-53065, upgrade to a patched version of the Linux kernel such as 6.11.8 or later.
Which versions of Linux Kernel are affected by CVE-2024-53065?
CVE-2024-53065 affects Linux Kernel versions from 6.11 to 6.12-rc6.
What type of vulnerability is CVE-2024-53065?
CVE-2024-53065 is a memory management issue related to duplicate kmem_cache creation.
Is CVE-2024-53065 a remote vulnerability?
CVE-2024-53065 is not classified as a remote vulnerability, it primarily affects local memory management.