[PATCH v6 09/14] x86/crash: Fix massive out-of-bounds write on 32-bit Highmem

sashiko-bot at kernel.org sashiko-bot at kernel.org
Mon Sep 21 02:12:57 PDT 2026


> On 32-bit x86 systems with HIGHMEM, kmap_local_page() only maps a single
> 4KB page. However, the elfcorehdr segment can span several pages (up to
> hundreds of kilobytes).
> 
> The original code blindly copies 'elfsz' bytes at once via
> memcpy_flushcache(), overwriting adjacent fixmap entries or critical
> virtual addresses.
> 
> Fix this by copying the new elfcorehdr page by page.
> 
> Cc: Thomas Gleixner <tglx at kernel.org>
> Cc: Ingo Molnar <mingo at redhat.com>
> Cc: Borislav Petkov <bp at alien8.de>
> Cc: Dave Hansen <dave.hansen at linux.intel.com>
> Cc: "H. Peter Anvin" <hpa at zytor.com>
> Cc: "Mike Rapoport (Microsoft)" <rppt at kernel.org>
> Cc: Vishal Verma <vishal.l.verma at intel.com>
> Cc: Baoquan He <baoquan.he at linux.dev>
> Cc: Chao Gao <chao.gao at intel.com>
> Cc: Sean Christopherson <seanjc at google.com>
> Cc: Eric DeVolder <eric.devolder at oracle.com>
> Cc: Hari Bathini <hbathini at linux.ibm.com>
> Cc: Andrew Morton <akpm at linux-foundation.org>
> Cc: Sourabh Jain <sourabhjain at linux.ibm.com>
> Cc: stable at vger.kernel.org
> Fixes: ea53ad9cf73b ("x86/crash: add x86 crash hotplug support")
> Link: https://sashiko.dev/#/patchset/20260907125404.922123-1-ruanjinjie%40huawei.com
> Signed-off-by: Jinjie Ruan <ruanjinjie at huawei.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921090450.807575-1-ruanjinjie@huawei.com?part=9




More information about the kexec mailing list