CVE-2026-98282

high

Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases. Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'.

References

https://git.kernel.org/stable/c/d6a1779129d936bc1fbab80181165da544eab736

https://git.kernel.org/stable/c/d48ceb6e1a6915c7bac4f902554a1047365cdff2

https://git.kernel.org/stable/c/9fd9c9bbb05417f468a11fb6d145d7ff61f4a868

https://git.kernel.org/stable/c/98d8dcc4ebd10523507d4478e148809a7771a213

https://git.kernel.org/stable/c/3776bf56e06980e8a12c8c0565d9e6ac44965f03

https://git.kernel.org/stable/c/314091243159f8e3749bc719bb129f423f72fd86

https://git.kernel.org/stable/c/0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71

https://git.kernel.org/stable/c/0543813753ef5cfbd6fa96694f7acf783fa01af7

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93210

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00138