CVE-2026-98216: IB/hfi1: Fix the PIO_CRED credit-return mmap
IB/hfi1: Fix the PIOCRED credit-return mmap
IB/hfi1: Fix the PIOCRED credit-return mmap
It occurs when a hardware send context's credit-return entry is on the second or third page of the per-node allocation, which happens once the send context index reaches 64 or 128. Entries on the first page use a zero offset and work correctly, making the failure intermittent.
The failure is triggered when user space accesses the PIO_CRED mapping returned by hfi1_file_mmap(). The first user-space read of the incorrectly mapped page can cause the fault.
With an IOMMU, the invalid address may not belong to any vmalloc area, causing page lookup to return no pages and a frame above MAXPHYADDR to be installed. A subsequent user read can produce a "Corrupted page table" message, such as one associated with psm2_ep_open_pr.