{"id":"DEBIAN-CVE-2023-53649","details":"In the Linux kernel, the following vulnerability has been resolved:  perf trace: Really free the evsel-\u003epriv area  In 3cb4d5e00e037c70 (\"perf trace: Free syscall tp fields in evsel-\u003epriv\") it only was freeing if strcmp(evsel-\u003etp_format-\u003esystem, \"syscalls\") returned zero, while the corresponding initialization of evsel-\u003epriv was being performed if it was _not_ zero, i.e. if the tp system wasn't 'syscalls'.  Just stop looking for that and free it if evsel-\u003epriv was set, which should be equivalent.  Also use the pre-existing evsel_trace__delete() function.  This resolves these leaks, detected with:    $ make EXTRA_CFLAGS=\"-fsanitize=address\" BUILD_BPF_SKEL=1 CORESIGHT=1 O=/tmp/build/perf-tools-next -C tools/perf install-bin    =================================================================   ==481565==ERROR: LeakSanitizer: detected memory leaks    Direct leak of 40 byte(s) in 1 object(s) allocated from:       #0 0x7f7343cba097 in calloc (/lib64/libasan.so.8+0xba097)       #1 0x987966 in zalloc (/home/acme/bin/perf+0x987966)       #2 0x52f9b9 in evsel_trace__new /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:307       #3 0x52f9b9 in evsel__syscall_tp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:333       #4 0x52f9b9 in evsel__init_raw_syscall_tp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:458       #5 0x52f9b9 in perf_evsel__raw_syscall_newtp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:480       #6 0x540e8b in trace__add_syscall_newtp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:3212       #7 0x540e8b in trace__run /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:3891       #8 0x540e8b in cmd_trace /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:5156       #9 0x5ef262 in run_builtin /home/acme/git/perf-tools-next/tools/perf/perf.c:323       #10 0x4196da in handle_internal_command /home/acme/git/perf-tools-next/tools/perf/perf.c:377       #11 0x4196da in run_argv /home/acme/git/perf-tools-next/tools/perf/perf.c:421       #12 0x4196da in main /home/acme/git/perf-tools-next/tools/perf/perf.c:537       #13 0x7f7342c4a50f in __libc_start_call_main (/lib64/libc.so.6+0x2750f)    Direct leak of 40 byte(s) in 1 object(s) allocated from:       #0 0x7f7343cba097 in calloc (/lib64/libasan.so.8+0xba097)       #1 0x987966 in zalloc (/home/acme/bin/perf+0x987966)       #2 0x52f9b9 in evsel_trace__new /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:307       #3 0x52f9b9 in evsel__syscall_tp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:333       #4 0x52f9b9 in evsel__init_raw_syscall_tp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:458       #5 0x52f9b9 in perf_evsel__raw_syscall_newtp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:480       #6 0x540dd1 in trace__add_syscall_newtp /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:3205       #7 0x540dd1 in trace__run /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:3891       #8 0x540dd1 in cmd_trace /home/acme/git/perf-tools-next/tools/perf/builtin-trace.c:5156       #9 0x5ef262 in run_builtin /home/acme/git/perf-tools-next/tools/perf/perf.c:323       #10 0x4196da in handle_internal_command /home/acme/git/perf-tools-next/tools/perf/perf.c:377       #11 0x4196da in run_argv /home/acme/git/perf-tools-next/tools/perf/perf.c:421       #12 0x4196da in main /home/acme/git/perf-tools-next/tools/perf/perf.c:537       #13 0x7f7342c4a50f in __libc_start_call_main (/lib64/libc.so.6+0x2750f)    SUMMARY: AddressSanitizer: 80 byte(s) leaked in 2 allocation(s).   [root@quaco ~]#  With this we plug all leaks with \"perf trace sleep 1\".","modified":"2026-09-15T09:02:51.934384536Z","published":"2025-10-07T16:15:48.380Z","upstream":["CVE-2023-53649"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53649"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.55-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53649.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53649.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53649.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}