CVE-2026-46268
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
PCI/P2PDMA: Fix p2pmem_alloc_mmap() waarschuwingsvoorwaarde
Commit b7e282378773 heeft de oorspronkelijke paginarefcount van al gewijzigd
p2pdma-pagina van één naar nul, maar in p2pmem_alloc_mmap() gebruikt het
"VM_WARN_ON_ONCE_PAGE(!page_ref_count(pagina))" om de beginpagina te bevestigen
refcount mag niet nul zijn en het volgende wordt gerapporteerd wanneer
CONFIG_DEBUG_VM is ingeschakeld:
page: refcount:0 mapcount:0 mapping:000000000 0000000 index:0x0 pfn:0x380400000
vlaggen: 0x20000000002000(gereserveerd|knooppunt=0|zone=4)
raw: 0020000000002000 ff1100015e3ab440 0000000000000000 0000000000000000
rauw: 0000000000000000 000000000000 00000000ffffffffffffffffffffffffffffffffffffffffffffffff
pagina gedumpt omdat: VM_WARN_ON_ONCE_PAGE(!page_ref_count(pagina))
------------[hier knippen]------------
WAARSCHUWING: CPU: 5 PID: 449 bij drivers/pci/p2pdma.c:240 p2pmem_alloc_mmap+0x83a/0xa60
Fix door "page_ref_count(page)" te gebruiken als de bewering c overlevering.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition
Commit b7e282378773 has already changed the initial page refcount of
p2pdma page from one to zero, however, in p2pmem_alloc_mmap() it uses
"VM_WARN_ON_ONCE_PAGE(!page_ref_count(page))" to assert the initial page
refcount should not be zero and the following will be reported when
CONFIG_DEBUG_VM is enabled:
page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x380400000
flags: 0x20000000002000(reserved|node=0|zone=4)
raw: 0020000000002000 ff1100015e3ab440 0000000000000000 0000000000000000
raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000
page dumped because: VM_WARN_ON_ONCE_PAGE(!page_ref_count(page))
------------[ cut here ]------------
WARNING: CPU: 5 PID: 449 at drivers/pci/p2pdma.c:240 p2pmem_alloc_mmap+0x83a/0xa60
Fix by using "page_ref_count(page)" as the assertion condition.