CVE-2026-68324

Summary

In the Linux kernel, the following vulnerability has been resolved:

iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()

dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type].

When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory.

Fix by using sizeof(*lstat) to clear only the target entry.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux55ee5e67a59a1b6f388d7a1c7b24022145f47a3e < 3078d82e7fe9048a2b90a992e71af7cd7ef881faaffected
LinuxLinux55ee5e67a59a1b6f388d7a1c7b24022145f47a3e < 866a35735e56b9dc81cbc33899255134adf6d8b3affected
LinuxLinux55ee5e67a59a1b6f388d7a1c7b24022145f47a3e < d06fea9b85f038690f55e72fe0c45e113715a85aaffected
LinuxLinux55ee5e67a59a1b6f388d7a1c7b24022145f47a3e < 0e28ca1c3204b51068579defc904a0dfba5e5c57affected
LinuxLinux55ee5e67a59a1b6f388d7a1c7b24022145f47a3e < 754f8efe45f87e3a9c6871b645b2f9d46d1b407baffected
LinuxLinux5.14affected
LinuxLinux0 < 5.14unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References