iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()

Summary

CVECVE-2026-68324
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-10 13:20:22 UTC
Updated2026-08-10 13:20:22 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type]. When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory. Fix by using sizeof(*lstat) to clear only the target entry.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e 3078d82e7fe9048a2b90a992e71af7cd7ef881fa git Not specified
CNA Linux Linux affected 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e 866a35735e56b9dc81cbc33899255134adf6d8b3 git Not specified
CNA Linux Linux affected 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e d06fea9b85f038690f55e72fe0c45e113715a85a git Not specified
CNA Linux Linux affected 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e 0e28ca1c3204b51068579defc904a0dfba5e5c57 git Not specified
CNA Linux Linux affected 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e 754f8efe45f87e3a9c6871b645b2f9d46d1b407b git Not specified
CNA Linux Linux affected 5.14 Not specified
CNA Linux Linux unaffected 5.14 semver Not specified
CNA Linux Linux unaffected 6.6.148 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.101 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.42 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.6 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc5 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report