CVE-2026-98003

Summary

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: Do not reallocate GA log buffers on resume

Commit c5e1a1eb9279 ("iommu/amd: Simplify and Consolidate Virtual APIC (AVIC) Enablement") moved the GA log allocation from iommu_init_pci() to enable_iommus_vapic(), which is called on every resume.

iommu_init_ga_log() assigns iommu->ga_log and iommu->ga_log_tail unconditionally. Each resume therefore replaces the boot-time pointers and leaks both old allocations. The function also uses GFP_KERNEL from a syscore resume callback, where interrupts are disabled and the non-boot CPUs are offline.

Return early if both buffers are already allocated. Clear the pointers in free_ga_log() so a partial allocation failure cannot leave ga_log dangling.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc5e1a1eb9279fdb28d47ca2a4493a4c53b7d6a0b < 94458b80d3b203c1c9e2c98aa7319b7713e006c0affected
LinuxLinuxc5e1a1eb9279fdb28d47ca2a4493a4c53b7d6a0b < b6be275d19cee01f8f1f08a2ff18337103d05d40affected
LinuxLinuxc5e1a1eb9279fdb28d47ca2a4493a4c53b7d6a0b < 00a7dd64888d6dd72110b40e2824a088cf7b7386affected
LinuxLinux6.0affected
LinuxLinux0 < 6.0unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References