CVE-2023-52490

    Dashboard / Vulnerabilities / CVE-2023-52490

    CVE-2023-52490

    Published: 29 Feb 2024Last Modified: 8 Oct 2026

    Summary: mm: migrate: fix getting incorrect page mapping during page migration

    Details: In the Linux kernel, the following vulnerability has been resolved: mm: migrate: fix getting incorrect page mapping during page migration When running stress-ng testing, we found below kernel crash after a few hours: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc : dentry_name+0xd8/0x224 lr : pointer+0x22c/0x370 sp : ffff800025f134c0 ...... Call trace: dentry_name+0xd8/0x224 pointer+0x22c/0x370 vsnprintf+0x1ec/0x730 vscnprintf+0x2c/0x60 vprintk_store+0x70/0x234 vprintk_emit+0xe0/0x24c vprintk_default+0x3c/0x44 vprintk_func+0x84/0x2d0 printk+0x64/0x88 __dump_page+0x52c/0x530 dump_page+0x14/0x20 set_migratetype_isolate+0x110/0x224 start_isolate_page_range+0xc4/0x20c offline_pages+0x124/0x474 memory_block_offline+0x44/0xf4 memory_subsys_offline+0x3c/0x70 device_offline+0xf0/0x120 ...... After analyzing the vmcore, I found this issue is caused by page migration. The scenario is that, one thread is doing page migration, and we will use the target page's ->mapping field to save 'anon_vma' pointer between page unmap and page move, and now the target page is locked and refcount is 1. Currently, there is another stress-ng thread performing memory hotplug, attempting to offline the target page that is being migrated. It discovers that the refcount of this target page is 1, preventing the offline operation, thus proceeding to dump the page. However, page_mapping() of the target page may return an incorrect file mapping to crash the system in dump_mapping(), since the target page->mapping only saves 'anon_vma' pointer without setting PAGE_MAPPING_ANON flag. There are seveval ways to fix this issue: (1) Setting the PAGE_MAPPING_ANON flag for target page's ->mapping when saving 'anon_vma', but this can confuse PageAnon() for PFN walkers, since the target page has not built mappings yet. (2) Getting the page lock to call page_mapping() in __dump_page() to avoid crashing the system, however, there are still some PFN walkers that call page_mapping() without holding the page lock, such as compaction. (3) Using target page->private field to save the 'anon_vma' pointer and 2 bits page state, just as page->mapping records an anonymous page, which can remove the page_mapping() impact for PFN walkers and also seems a simple way. So I choose option 3 to fix this issue, and this can also fix other potential issues for PFN walkers, such as compaction.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 64c8902ed4418317cd416c566f896bd4a92b2efc

    Affected versions

    v6.1.189
    v6.1.188
    v6.1.187
    v6.1.186
    v6.1.185
    v6.1.184
    v6.1.183
    v6.1.182
    v6.1.181
    v6.1.180
    v6.1.179
    v6.1.178
    v6.1.177
    v6.1.176
    v6.1.175
    v6.1.174
    v6.1.173
    v6.1.172
    v6.1.171
    v6.1.170
    v6.1.169
    v6.1.168
    v6.1.167
    v6.1.166
    v6.1.165
    v6.1.164
    v6.1.163
    v6.1.162
    v6.1.161
    v6.1.160
    v6.1.159
    v6.1.158
    v6.1.157
    v6.1.156
    v6.1.155
    v6.1.154
    v6.1.153
    v6.1.152
    v6.1.151
    v6.1.150
    v6.1.149
    v6.1.148
    v6.1.147
    v6.1.146
    v6.1.145
    v6.1.144
    v6.1.143
    v6.1.142
    v6.1.141
    v6.1.140
    v6.1.139
    v6.1.138
    v6.1.137
    v6.1.136
    v6.1.135
    v6.1.134
    v6.1.133
    v6.1.132
    v6.1.131
    v6.1.130
    v6.1.129
    v6.1.128
    v6.1.127
    v6.1.126
    v6.1.125
    v6.1.124
    v6.1.123
    v6.1.122
    v6.1.121
    v6.1.120
    v6.1.119
    v6.1.118
    v6.1.117
    v6.1.116

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-52490 | CVE-DB