Skip to content

Downstream oss mem fixes - #18030

Closed
behlendorf wants to merge 4 commits into
openzfs:masterfrom
behlendorf:downstream-oss-mem-fixes
Closed

behlendorf wants to merge 4 commits into
openzfs:masterfrom
behlendorf:downstream-oss-mem-fixes

Conversation

@behlendorf

Copy link
Copy Markdown
Contributor

Motivation and Context

Replaces #17973. I've opened to PR to test the final patch set.

The following small changes have been made from the original:

  1. squashed style cleanup changes in to the appropriate commits,
  2. declare struct page * where it's assigned in abd_iter_map and abd_iter_unmap.
  3. added commit to exclude "signed-off-by/reviewed-by" lines from commitcheck target.
    This really should be its own PR, but it's trivial enough I included it here as a separate commit.

Description

See #17973 and #15668 for details.

How Has This Been Tested?

The change is identical to the updated #17973 with the exception of 2. above.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Performance enhancement (non-breaking change which improves efficiency)
  • Code cleanup (non-breaking change which makes code smaller or more readable)
  • Quality assurance (non-breaking change which makes the code more robust against bugs)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Library ABI change (libzfs, libzfs_core, libnvpair, libuutil and libzfsbootenv)
  • Documentation (a change to man pages or other documentation)

HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Copilot AI review requested due to automatic review settings December 8, 2025 23:36
@behlendorf behlendorf mentioned this pull request Dec 8, 2025
1 of 14 tasks
@behlendorf behlendorf added the Status: Code Review Needed Ready for review and testing label Dec 8, 2025

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses memory-related bugs in ZFS's handling of high memory pages on Linux systems. The changes ensure proper page boundary handling when mapping and unmapping memory regions, fixing potential memory corruption issues.

Key changes:

  • Fixed highmem page handling in ABD iterator map/unmap operations to properly handle multi-page scatter-gather lists
  • Corrected page boundary calculations in bio_vec operations to prevent out-of-bounds memory access
  • Reordered unmap operations in RAIDZ generation to ensure correct cleanup sequence
  • Enhanced commit message checking to exempt signed-off-by/reviewed-by lines from length limits

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
scripts/commitcheck.sh Added filters to exempt signed-off-by and reviewed-by lines from 72-character length check
module/zfs/abd.c Reordered unmap loop to occur after data ABD cleanup in RAIDZ generation
module/os/linux/zfs/zfs_uio.c Fixed page offset and size calculations for multi-page bio_vec handling
module/os/linux/zfs/abd_os.c Added highmem page handling with nth_page() and proper offset masking in ABD iterators

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread module/zfs/abd.c Outdated
bspengler-oss and others added 3 commits December 8, 2025 16:07
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Signed-off-by: Brian Behlendorf 
@behlendorf
behlendorf force-pushed the downstream-oss-mem-fixes branch from 81cb3ea to 62f8206 Compare December 9, 2025 00:08
Comment thread module/os/linux/zfs/abd_os.c

@robn robn left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This makes sense to me. One question about an API detail but I don't think it changes anything for now.

@behlendorf behlendorf added Status: Accepted Ready to integrate (reviewed, tested) and removed Status: Code Review Needed Ready for review and testing labels Dec 9, 2025
@behlendorf behlendorf closed this in 87df5e4 Dec 9, 2025
behlendorf pushed a commit that referenced this pull request Dec 9, 2025
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes #15668
Closes #18030
behlendorf pushed a commit that referenced this pull request Dec 9, 2025
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes #15668
Closes #18030
behlendorf added a commit that referenced this pull request Dec 9, 2025
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes #18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf added a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf added a commit to behlendorf/zfs that referenced this pull request Dec 10, 2025
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
@sempervictus

Copy link
Copy Markdown
Contributor

@behlendorf can these be backported to stable releases? It looks like they're staged for 2.4.0 but they're been needed on my system to boot the root pool since 2.3.1 i believe.

@behlendorf

Copy link
Copy Markdown
Contributor Author

@sempervictus yes, we'll want to pull these in for the next 2.3.x release.

@sempervictus

Copy link
Copy Markdown
Contributor

Thank you!

kithrup pushed a commit to KlaraSystems/zfs that referenced this pull request Dec 17, 2025
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
kithrup pushed a commit to KlaraSystems/zfs that referenced this pull request Dec 17, 2025
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
kithrup pushed a commit to KlaraSystems/zfs that referenced this pull request Dec 17, 2025
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
kithrup pushed a commit to KlaraSystems/zfs that referenced this pull request Dec 17, 2025
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 17, 2025
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 17, 2025
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf pushed a commit to behlendorf/zfs that referenced this pull request Dec 17, 2025
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
behlendorf added a commit to behlendorf/zfs that referenced this pull request Dec 17, 2025
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
behlendorf pushed a commit that referenced this pull request Dec 20, 2025
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes #15668
Closes #18030
behlendorf pushed a commit that referenced this pull request Dec 20, 2025
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes #15668
Closes #18030
behlendorf pushed a commit that referenced this pull request Dec 20, 2025
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes #15668
Closes #18030
behlendorf added a commit that referenced this pull request Dec 20, 2025
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes #18030
lundman pushed a commit to openzfsonosx/openzfs-fork that referenced this pull request Feb 5, 2026
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonosx/openzfs-fork that referenced this pull request Feb 5, 2026
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonosx/openzfs-fork that referenced this pull request Feb 5, 2026
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonosx/openzfs-fork that referenced this pull request Feb 5, 2026
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
HIGHMEM kmap interfaces operate on only a single page at a time
yet ZFS hadn't accounted for this, resulting in crashes and
potential memory corruption on HIGHMEM (typically 32-bit) systems.
This was caught by PaX's KERNSEAL feature as it makes use of
HIGHMEM functionality on x64.

On typical 64-bit systems, this issue wouldn't have been observed,
as the map interfaces simply fall back to returning an address in
lowmem where the contiguous pages can be accessed directly.

Joint work with the PaX Team, tested by Mark van Dijk

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
ZFS typically preserves proper LIFO ordering regarding map/unmap
operations that wrap the Linux kernel's kmap interfaces that
require such ordering, but one instance in abd_raidz_gen_iterate()
did not.

Similar issues have been fixed in the Linux kernel in the past,
see for instance CVE-2025-39899 for userfaultfd.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
Fix another instance where ZFS assumes multiple pages can be
mapped at once via zfs_kmap_local(), resulting in crashes and
potential memory corruption on HIGHMEM-enabled (typically 32-bit)
systems.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Reviewed-by: Brian Behlendorf 
Signed-off-by: bspengler-oss <94915855+bspengler-oss@users.noreply.github.com>
Closes openzfs#15668
Closes openzfs#18030
lundman pushed a commit to openzfsonwindows/openzfs that referenced this pull request Feb 23, 2026
Allow an author or reviewer's name and email address to exceed
the 72 character limit enforced by the commitcheck target.

Reviewed-by: RageLtMan 
Reviewed-by: Rob Norris 
Signed-off-by: Brian Behlendorf 
Closes openzfs#18030
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Status: Accepted Ready to integrate (reviewed, tested)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants