CVE-2026-98282
Received
Received - Intake
Buffer Overflow Fix in Linux Kernel PowerPC IOMMU
Vulnerability report for CVE-2026-98282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.
Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | b1af23d836f811137d504d14d4cbdd01929dec34 |
| Linux | Linux | 4.12 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |