« Volver al listado

CVE-2026-98216

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

IB/hfi1: Fix the PIO_CRED credit-return mmap

hfi1_file_mmap()'s PIO_CRED case must hand user space the single credit-return page that holds this context's entry. That page is the second or third page of the per-node credit-return allocation once the hardware send context index reaches 64 or 128, so the failure below is intermittent: when the entry lands on the first page the offset is zero and everything works.

Two things are wrong.

First, cr_page_offset is a byte offset but .va is a struct credit_return *, so adding it is pointer arithmetic and scales the offset by sizeof(struct credit_return) == 64. memvirt then lands 256 KiB or 512 KiB past a 10240-byte allocation.

Leer descripción completaMostrar menos

With an IOMMU translating, that address is inside the vmalloc range but in no vm_area, so dma_mmap_coherent() -> iommu_dma_mmap() finds no pages, vmalloc_to_pfn() returns page_to_pfn(NULL), and remap_pfn_range() installs a frame above MAXPHYADDR. The first user read then takes:

Second, and still wrong once the arithmetic is corrected, dma_mmap_coherent() describes a whole coherent buffer and selects the page within it with vma->vm_pgoff. Offsetting cpu_addr has no effect: for a vmap'd allocation iommu_dma_mmap() uses cpu_addr only to locate the vm_area and then maps pages[vm_pgoff], which hfi1_file_mmap() has just set to 0. User space therefore always receives the first credit-return page, every credit read is for the wrong context, and send PIO stalls forever.

Use the DMA API as intended: pass the base of the allocation with its full length and select the page with vm_pgoff. A separate length is needed because memlen must keep describing the VMA for the existing size check. The dma-direct path stays correct as well, since dma_direct_mmap() adds the same vm_pgoff to the base pfn.

Tested on a Dell T7610 (Xeon E5-2650 v2, Intel IOMMU in DMA-FQ mode) against a Threadripper PRO 3995WX peer, both Omni-Path 100. Before this change psm2_ep_open() Oopses the kernel; with only the arithmetic corrected psm2_ep_open() succeeds but any transfer that uses send PIO hangs, PSM2_SDMA=2 (send PIO disabled) completing normally while PSM2_SDMA=0 (send PIO only) hangs every time. With this change send PIO, send DMA and the default mixed mode all work.

Detalles técnicos trazas, registros y código del informe original
  psm2_ep_open_pr: Corrupted page table at address 7a14d007e000
  PGD 800000013886a067 P4D 800000013886a067 PUD 13886b067 PMD 13886c067
                                            PTE 800049168e911235
  Oops: Bad pagetable: 000d [#1] SMP PTI

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98216",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1ec82317a1daac78c04b0c15af89018ccf9fa2b7",
              "lessThan": "535530bb2ea5254e1e9f55280143d262dd065204",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ec82317a1daac78c04b0c15af89018ccf9fa2b7",
              "lessThan": "dcebe0b0bb080a25fe08011fd6b6e741f7912f01",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ec82317a1daac78c04b0c15af89018ccf9fa2b7",
              "lessThan": "180752deb7270ad37394ab6ef7cf4978fad040b3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ec82317a1daac78c04b0c15af89018ccf9fa2b7",
              "lessThan": "bafeac9ce5d1ce5256bcf7e5702e831e9aaf419b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ec82317a1daac78c04b0c15af89018ccf9fa2b7",
              "lessThan": "62f0f34fbd2b2d5653d33d3b9d42fdcabb1c0101",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/hfi1/file_ops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/hw/hfi1/file_ops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:08.260",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/180752deb7270ad37394ab6ef7cf4978fad040b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/535530bb2ea5254e1e9f55280143d262dd065204",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/62f0f34fbd2b2d5653d33d3b9d42fdcabb1c0101",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bafeac9ce5d1ce5256bcf7e5702e831e9aaf419b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dcebe0b0bb080a25fe08011fd6b6e741f7912f01",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix the PIO_CRED credit-return mmap\n\nhfi1_file_mmap()'s PIO_CRED case must hand user space the single\ncredit-return page that holds this context's entry.  That page is the\nsecond or third page of the per-node credit-return allocation once the\nhardware send context index reaches 64 or 128, so the failure below is\nintermittent: when the entry lands on the first page the offset is zero\nand everything works.\n\nTwo things are wrong.\n\nFirst, cr_page_offset is a byte offset but .va is a struct\ncredit_return *, so adding it is pointer arithmetic and scales the offset\nby sizeof(struct credit_return) == 64.  memvirt then lands 256 KiB or\n512 KiB past a 10240-byte allocation.  With an IOMMU translating, that\naddress is inside the vmalloc range but in no vm_area, so\ndma_mmap_coherent() -> iommu_dma_mmap() finds no pages, vmalloc_to_pfn()\nreturns page_to_pfn(NULL), and remap_pfn_range() installs a frame above\nMAXPHYADDR.  The first user read then takes:\n\n  psm2_ep_open_pr: Corrupted page table at address 7a14d007e000\n  PGD 800000013886a067 P4D 800000013886a067 PUD 13886b067 PMD 13886c067\n                                            PTE 800049168e911235\n  Oops: Bad pagetable: 000d [#1] SMP PTI\n\nSecond, and still wrong once the arithmetic is corrected,\ndma_mmap_coherent() describes a whole coherent buffer and selects the\npage within it with vma->vm_pgoff.  Offsetting cpu_addr has no effect:\nfor a vmap'd allocation iommu_dma_mmap() uses cpu_addr only to locate the\nvm_area and then maps pages[vm_pgoff], which hfi1_file_mmap() has just\nset to 0.  User space therefore always receives the first credit-return\npage, every credit read is for the wrong context, and send PIO stalls\nforever.\n\nUse the DMA API as intended: pass the base of the allocation with its\nfull length and select the page with vm_pgoff.  A separate length is\nneeded because memlen must keep describing the VMA for the existing size\ncheck.  The dma-direct path stays correct as well, since dma_direct_mmap()\nadds the same vm_pgoff to the base pfn.\n\nTested on a Dell T7610 (Xeon E5-2650 v2, Intel IOMMU in DMA-FQ mode)\nagainst a Threadripper PRO 3995WX peer, both Omni-Path 100.  Before this\nchange psm2_ep_open() Oopses the kernel; with only the arithmetic\ncorrected psm2_ep_open() succeeds but any transfer that uses send PIO\nhangs, PSM2_SDMA=2 (send PIO disabled) completing normally while\nPSM2_SDMA=0 (send PIO only) hangs every time.  With this change send PIO,\nsend DMA and the default mixed mode all work."
    }
  ],
  "lastModified": "2026-10-06T09:18:08.260",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}