CVE-2026-97593
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX
When using a 5-level translation table via ZPCI_TABLE_TYPE_RFX get_rso_from_iova() returns NULL when the region-first entry is invalid. Yet in get_rto_from_iova() the region-second origin rso is not checked to be non-NULL before accessing rso[rsx] leading to a NULL pointer dereference instead of a NULL return when iova_to_phys() is called on a unmapped IOVA. Fix this by adding the missing NULL check.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 81244074b518aeb90de5f68e7e825564c29c5c50 < d0502ed0a1aae97e2ab7a21545903ba612d9f02e | affected |
| Linux | Linux | 81244074b518aeb90de5f68e7e825564c29c5c50 < 41b5e0ce6801bf04d8fd3bca46e8c393349ebd5c | affected |
| Linux | Linux | 81244074b518aeb90de5f68e7e825564c29c5c50 < 20db6573301e66cd65ebf6c130b6563c69374d9d | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/d0502ed0a1aae97e2ab7a21545903ba612d9f02e
- https://git.kernel.org/stable/c/41b5e0ce6801bf04d8fd3bca46e8c393349ebd5c
- https://git.kernel.org/stable/c/20db6573301e66cd65ebf6c130b6563c69374d9d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.