Executive brief
The Linux kernel's RISC-V memory management incorrectly aligns virtual memory maps to physical memory addresses, causing a mismatch that can lead to memory corruption on systems where DRAM does not align to specific boundaries. This affects the kernel's ability to manage memory safely, potentially allowing system crashes or enabling privilege escalation attacks on vulnerable systems.
Technical details
The vulnerability stems from a unit mismatch in RISC-V memory initialization: VMEMMAP_ADDR_ALIGN was computed using MAX_FOLIO_VMEMMAP_ALIGN (measured in bytes of struct page storage) to align physical addresses, but the two operate in different domains. The kernel's mask-based compound_info encoding requires pfn_to_page(0) to be naturally aligned to MAX_FOLIO_VMEMMAP_ALIGN. A check added in commit 9f94db4c7eaa exposed this flaw on systems (such as QEMU virt) where the DRAM base is not aligned to MAX_FOLIO_NR_PAGES * PAGE_SIZE, triggering a kernel warning during sparse_init(). The fix converts MAX_FOLIO_VMEMMAP_ALIGN to the equivalent physical alignment before using it in VMEMMAP_ADDR_ALIGN, ensuring the resulting vmemmap base satisfies alignment requirements without changing the round_down() logic.
Affected products
- Linux Linux Kernel 7.2-rc3 and likely earlier versions
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Fix applied via commit converting MAX_FOLIO_VMEMMAP_ALIGN to physical alignment domain