UNKNOWN NVD
CVE-2026-98282
In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8
In the Linux kernel, the following vulnerability has been resolved:
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.
Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.
References
- https://git.kernel.org/stable/c/0543813753ef5cfbd6fa96694f7acf783fa01af7
- https://git.kernel.org/stable/c/0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71
- https://git.kernel.org/stable/c/314091243159f8e3749bc719bb129f423f72fd86
- https://git.kernel.org/stable/c/3776bf56e06980e8a12c8c0565d9e6ac44965f03
- https://git.kernel.org/stable/c/98d8dcc4ebd10523507d4478e148809a7771a213
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 11356 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.