CVE-2026-46013
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
mm/memfd_luo: fix fysieke adresconversie in put_folios cleanup
In memfd_luo_retrieve_folios()'s put_folios cleanup path:
1. kho_restore_folio() verwacht een phys_addr_t (fysiek adres) maar
ontvangt een ruwe PFN (portefeuille->pfn). Dit zorgt ervoor dat kho_restore_page()
controleer het verkeerde fysieke adres (pfn <pfn check that exists in the main
ophaallus en memfd_luo_discard_folios(), die
onjuiste verwerking van schaarse vijlgaten waarbij pfn=0. Fix door PFN om te zetten naar fysiek adres met PFN_PHYS() en toe te voegen
de ! portefeuille- >pfn-check, die overeenkomt met het patroon dat elders in dit bestand wordt gebruikt. Dit probleem werd geïdentificeerd door de AI-beoordeling. https://sashiko.dev/#/patchset/20260323110747.193569-1-duanchenghao@kylinos.cn
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
mm/memfd_luo: fix physical address conversion in put_folios cleanup
In memfd_luo_retrieve_folios()'s put_folios cleanup path:
1. kho_restore_folio() expects a phys_addr_t (physical address) but
receives a raw PFN (pfolio->pfn). This causes kho_restore_page() to
check the wrong physical address (pfn <pfn check that exists in the main
retrieval loop and memfd_luo_discard_folios(), which could
incorrectly process sparse file holes where pfn=0.
Fix by converting PFN to physical address with PFN_PHYS() and adding
the !pfolio->pfn check, matching the pattern used elsewhere in this file.
This issue was identified by the AI review.
https://sashiko.dev/#/patchset/20260323110747.193569-1-duanchenghao@kylinos.cn