CVE-2026-98282

Summary

In the Linux kernel, the following vulnerability has been resolved:

powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba

The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases.

Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < 98d8dcc4ebd10523507d4478e148809a7771a213affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < 9fd9c9bbb05417f468a11fb6d145d7ff61f4a868affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < 3776bf56e06980e8a12c8c0565d9e6ac44965f03affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < d6a1779129d936bc1fbab80181165da544eab736affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < d48ceb6e1a6915c7bac4f902554a1047365cdff2affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < 0543813753ef5cfbd6fa96694f7acf783fa01af7affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < 314091243159f8e3749bc719bb129f423f72fd86affected
LinuxLinuxb1af23d836f811137d504d14d4cbdd01929dec34 < 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71affected
LinuxLinux4.12affected
LinuxLinux0 < 4.12unaffected
LinuxLinux5.10.271 <= 5.10.*unaffected
LinuxLinux5.15.222 <= 5.15.*unaffected
LinuxLinux6.1.189 <= 6.1.*unaffected
LinuxLinux6.6.158 <= 6.6.*unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References