powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
Summary
| CVE | CVE-2026-98282 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 09:18:18 UTC |
| Updated | 2026-10-07 07:17:07 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases. Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.001840000 probability, percentile 0.073050000 (date 2026-10-06)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 98d8dcc4ebd10523507d4478e148809a7771a213 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 9fd9c9bbb05417f468a11fb6d145d7ff61f4a868 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 3776bf56e06980e8a12c8c0565d9e6ac44965f03 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 d6a1779129d936bc1fbab80181165da544eab736 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 d48ceb6e1a6915c7bac4f902554a1047365cdff2 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 0543813753ef5cfbd6fa96694f7acf783fa01af7 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 314091243159f8e3749bc719bb129f423f72fd86 git | Not specified |
| CNA | Linux | Linux | affected b1af23d836f811137d504d14d4cbdd01929dec34 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 git | Not specified |
| CNA | Linux | Linux | affected 4.12 | Not specified |
| CNA | Linux | Linux | unaffected 4.12 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.271 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.222 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.189 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.158 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.112 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.54 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.8 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc4 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/98d8dcc4ebd10523507d4478e148809a7771a213 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/314091243159f8e3749bc719bb129f423f72fd86 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d6a1779129d936bc1fbab80181165da544eab736 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d48ceb6e1a6915c7bac4f902554a1047365cdff2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3776bf56e06980e8a12c8c0565d9e6ac44965f03 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9fd9c9bbb05417f468a11fb6d145d7ff61f4a868 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0543813753ef5cfbd6fa96694f7acf783fa01af7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.