{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98282","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.335Z","datePublished":"2026-10-06T08:45:43.775Z","dateUpdated":"2026-10-07T06:49:53.499Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:53.499Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba\n\nThe commit b1af23d836f8 (\"KVM: PPC: iommu: Unify TCE checking\") unified\nIOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().\nWhile doing so, the passed in argument npages is ignored and constant\nvalue '1' is used leaving out a possible overflow as the callers can\nlegitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT\ncases.\n\nFix this by accounting for 'npages', checking for arithmetic overflow,\nand verifying that the entire requested range (ioba - offset + npages)\ndoes not exceed the table capacity 'size'."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bad ioba/npages values come from a KVM guest's H_STUFF_TCE or H_PUT_TCE_INDIRECT hypercall registers. book3s_hv.c passes them to kvmppc_h_stuff_tce()/kvmppc_h_put_tce_indirect(), which call kvmppc_ioba_validate() -> iommu_tce_check_ioba(). The attacker is code running on the host in a guest, not a remote network peer.\nAC:L - The guest picks liobn, ioba (the last valid entry) and npages itself. The flawed check only tests ioba+1, so every such hypercall reliably walks kvmppc_tce_put() past stt->size. No race or outside condition is involved; only heap grooming affects how far exploitation goes.\nPR:L - The attacker needs kernel privilege inside their own guest, which any tenant of a pseries KVM VM has. Relative to the host, that is a low-privilege tenant position. The guest's TCE table already exists because QEMU creates it through KVM_CREATE_SPAPR_TCE_64 for the default PHB/VIO DMA windows.\nUI:N - The guest issues the hypercalls whenever it wants. No action by the host administrator or any other user is needed.\nS:C - A guest-controlled hypercall corrupts host kernel memory and touches the host's hardware IOMMU table outside the guest's DMA window. The impact therefore crosses the guest-to-host virtualization boundary.\nC:H - kvmppc_tce_put() and kvmppc_h_get_tce paths index stt->pages[] past the kmalloc'd flexible array, and the TCE iommu_unmap/map paths use entries beyond the window. This gives out-of-bounds access to host heap and IOMMU state that can be turned into host memory disclosure.\nI:H - In H_STUFF_TCE, npages is unbounded and tce_value is guest-chosen. kvmppc_tce_put() writes that 8-byte value through an out-of-bounds stt->pages[] pointer, or stores a newly allocated page pointer into the out-of-bounds slot. Both are host heap writes.\nA:H - Dereferencing an out-of-bounds stt->pages[] entry as a struct page, or corrupting the host heap and IOMMU tables, crashes or oopses the host. That takes down every VM running on it."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/powerpc/kernel/iommu.c"],"versions":[{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"98d8dcc4ebd10523507d4478e148809a7771a213","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"9fd9c9bbb05417f468a11fb6d145d7ff61f4a868","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"3776bf56e06980e8a12c8c0565d9e6ac44965f03","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"d6a1779129d936bc1fbab80181165da544eab736","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"d48ceb6e1a6915c7bac4f902554a1047365cdff2","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"0543813753ef5cfbd6fa96694f7acf783fa01af7","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"314091243159f8e3749bc719bb129f423f72fd86","status":"affected","versionType":"git"},{"version":"b1af23d836f811137d504d14d4cbdd01929dec34","lessThan":"0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/powerpc/kernel/iommu.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/98d8dcc4ebd10523507d4478e148809a7771a213"},{"url":"https://git.kernel.org/stable/c/9fd9c9bbb05417f468a11fb6d145d7ff61f4a868"},{"url":"https://git.kernel.org/stable/c/3776bf56e06980e8a12c8c0565d9e6ac44965f03"},{"url":"https://git.kernel.org/stable/c/d6a1779129d936bc1fbab80181165da544eab736"},{"url":"https://git.kernel.org/stable/c/d48ceb6e1a6915c7bac4f902554a1047365cdff2"},{"url":"https://git.kernel.org/stable/c/0543813753ef5cfbd6fa96694f7acf783fa01af7"},{"url":"https://git.kernel.org/stable/c/314091243159f8e3749bc719bb129f423f72fd86"},{"url":"https://git.kernel.org/stable/c/0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71"}],"title":"powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba","x_generator":{"engine":"bippy-1.2.0"}}}}