[PATCH v6 09/14] x86/crash: Fix massive out-of-bounds write on 32-bit Highmem
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Mon Sep 21 02:12:57 PDT 2026
> On 32-bit x86 systems with HIGHMEM, kmap_local_page() only maps a single
> 4KB page. However, the elfcorehdr segment can span several pages (up to
> hundreds of kilobytes).
>
> The original code blindly copies 'elfsz' bytes at once via
> memcpy_flushcache(), overwriting adjacent fixmap entries or critical
> virtual addresses.
>
> Fix this by copying the new elfcorehdr page by page.
>
> Cc: Thomas Gleixner <tglx at kernel.org>
> Cc: Ingo Molnar <mingo at redhat.com>
> Cc: Borislav Petkov <bp at alien8.de>
> Cc: Dave Hansen <dave.hansen at linux.intel.com>
> Cc: "H. Peter Anvin" <hpa at zytor.com>
> Cc: "Mike Rapoport (Microsoft)" <rppt at kernel.org>
> Cc: Vishal Verma <vishal.l.verma at intel.com>
> Cc: Baoquan He <baoquan.he at linux.dev>
> Cc: Chao Gao <chao.gao at intel.com>
> Cc: Sean Christopherson <seanjc at google.com>
> Cc: Eric DeVolder <eric.devolder at oracle.com>
> Cc: Hari Bathini <hbathini at linux.ibm.com>
> Cc: Andrew Morton <akpm at linux-foundation.org>
> Cc: Sourabh Jain <sourabhjain at linux.ibm.com>
> Cc: stable at vger.kernel.org
> Fixes: ea53ad9cf73b ("x86/crash: add x86 crash hotplug support")
> Link: https://sashiko.dev/#/patchset/20260907125404.922123-1-ruanjinjie%40huawei.com
> Signed-off-by: Jinjie Ruan <ruanjinjie at huawei.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921090450.807575-1-ruanjinjie@huawei.com?part=9
More information about the kexec
mailing list