KernelScan.io

HIGH Introduced in 6.3

hfi1 CreditReturn OOB

CVE-2026-98216

CVSS 7.1 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

KernelScan AI5.4MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix the PIO_CRED credit-return mmap hfi1_file_mmap()'s PIO_CRED case must hand user space the single credit-return page that holds this context's entry. That page is the second or third page of the per-node credit-return allocation once the hardware send context index reaches 64 or 128, so the failure below is intermittent: when the entry lands on the first page the offset is zero and everything works. Two things are wrong. First, cr_page_offset is a byte offset but .va is a struct credit_return *, so adding it is pointer arithmetic and scales the offset by sizeof(struct credit_return) == 64. memvirt then lands 256 KiB or 512 KiB past a 10240-byte allocation. With an IOMMU translating, that address is inside the vmalloc range but in no vm_area, so dma_mmap_coherent() -> iommu_dma_mmap() finds no pages, vmalloc_to_pfn() returns page_to_pfn(NULL), and remap_pfn_range() installs a frame above MAXPHYADDR. The first user read then takes: psm2_ep_open_pr: Corrupted page table at address 7a14d007e000 PGD 800000013886a067 P4D 800000013886a067 PUD 13886b067 PMD 13886c067 PTE 800049168e911235 Oops: Bad pagetable: 000d [#1] SMP PTI Second, and still wrong once the arithmetic is corrected, dma_mmap_coherent() describes a whole coherent buffer and selects the page within it with vma->vm_pgoff. Offsetting cpu_addr has no effect: for a vmap'd allocation iommu_dma_mmap() uses cpu_addr only to locate the vm_area and then maps pages[vm_pgoff], which hfi1_file_mmap() has just set to 0. User space therefore always receives the first credit-return page, every credit read is for the wrong context, and send PIO stalls forever. Use the DMA API as intended: pass the base of the allocation with its full length and select the page with vm_pgoff. A separate length is needed because memlen must keep describing the VMA for the existing size check. The dma-direct path stays correct as well, since dma_direct_mmap() adds the same vm_pgoff to the base pfn. Tested on a Dell T7610 (Xeon E5-2650 v2, Intel IOMMU in DMA-FQ mode) against a Threadripper PRO 3995WX peer, both Omni-Path 100. Before this change psm2_ep_open() Oopses the kernel; with only the arithmetic corrected psm2_ep_open() succeeds but any transfer that uses send PIO hangs, PSM2_SDMA=2 (send PIO disabled) completing normally while PSM2_SDMA=0 (send PIO only) hangs every time. With this change send PIO, send DMA and the default mixed mode all work.

02

Engine v0.7.0

Risk summary

A local user with access to an Intel Omni-Path (hfi1) InfiniBand device file can trigger a kernel oops by mmapping the PIO credit-return page. The bug stems from incorrect pointer arithmetic that produces an out-of-bounds virtual address, causing the DMA mapping API to install an invalid physical frame into the page table. The resulting 'Bad pagetable' oops denies service to the entire system. Additionally, even when the oops does not occur, the wrong credit-return page is always mapped, causing send PIO transfers to stall indefinitely.

Affecteddrivers/infiniband/hw/hfi1/file_ops.c (IB/hfi1)

Vulnerability analysis

When a local process mmaps the PIO credit-return page on an hfi1 InfiniBand device, the driver computes the page offset as a byte value but adds it to a typed pointer, causing C pointer arithmetic to scale the offset by the struct size and land hundreds of kilobytes past the actual allocation. The DMA mapping API then tries to map that invalid address, installing a page-table entry above the maximum physical address; the first user-space read of that page triggers a kernel 'Bad pagetable' oops. A second defect zeroes the page-offset field before the mapping call, so even with corrected arithmetic user space always receives the first credit-return page — the wrong context's data — and send PIO stalls forever. The fix passes the base of the allocation with its full length and lets the DMA API select the correct page via the page-offset field, as the API contract intends. A local user with access to the hfi1 device file on a system with Omni-Path hardware present can reach this path; no network access is needed.

03

BranchIntroducedFixed inPatch commit
6.66.36.6.158535530bb2ea5
6.126.36.12.112dcebe0b0bb08
6.186.36.18.54180752deb727
7.26.37.2.8bafeac9ce5d1
mainline6.37.3-rc462f0f34fbd2b