CVE-2026-64186
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs
In iommu_mmio_write() and iommu_capability_write(), the variables dbg_mmio_offset and dbg_cap_offset are declared as int. However, they are populated using kstrtou32_from_user(). If a user provides a sufficiently large value, it can become a negative integer.
Prior to this patch, the AMD IOMMU debugfs implementation was already protected by different mechanisms.
- #define OFS_IN_SZ 8 ensures the user string <= 8 bytes, so e.g. 0xffffffff isn't a valid input.
if (cnt > OFS_IN_SZ) return -EINVAL;
- Implicit type promotion in iommu_mmio_write(), dbg_mmio_offset is int and iommu->mmio_phys_end is u64
if (dbg_mmio_offset > iommu->mmio_phys_end - sizeof(u64)) return -EINVAL;
- The show handlers would currently catch the negative number and refuse to perform the read.
Replace kstrtou32_from_user() with kstrtos32_from_user() to parse the input, and check for negative values to explicitly prevent out-of-bounds memory accesses directly in iommu_mmio_write() and iommu_capability_write().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 7a4ee419e8c144b747a8915856e91a034d7c8f34 < 488d2c76bd9f78433a70690d1054bfae3d39a407 | affected |
| Linux | Linux | 7a4ee419e8c144b747a8915856e91a034d7c8f34 < 62f9dfbf1aceae88b03c5ca08f7d36e943939dec | affected |
| Linux | Linux | 7a4ee419e8c144b747a8915856e91a034d7c8f34 < 8dfd3d8d74435344ee8dc9237596959c8b2a6cbe | affected |
| Linux | Linux | 6.17 | affected |
| Linux | Linux | 0 < 6.17 | unaffected |
| Linux | Linux | 6.18.34 <= 6.18.* | unaffected |
| Linux | Linux | 7.0.11 <= 7.0.* | unaffected |
| Linux | Linux | 7.1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/488d2c76bd9f78433a70690d1054bfae3d39a407
- https://git.kernel.org/stable/c/62f9dfbf1aceae88b03c5ca08f7d36e943939dec
- https://git.kernel.org/stable/c/8dfd3d8d74435344ee8dc9237596959c8b2a6cbe
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.