PT-2026-64510 · Linux · Linux

CVE-2026-64289

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Set upper bounds on cache invalidation entry num and entry len
iommufd hwpt invalidate() takes a user-controlled entry num and entry len, each bounded only by U32 MAX. An entry len beyond the kernel's struct size makes the copy helper verify the extra bytes are zero, scanning that excess in one uninterruptible pass; a multi-gigabyte value over zeroed user memory trips the soft-lockup watchdog.
A large entry num is the other half, driving the backend invalidation loop with no reschedule. The VT-d nested handler, for one, copies each entry and flushes caches per iteration, pinning the CPU on a non-preemptible kernel.
Cap both in the ioctl. entry len is held under PAGE SIZE, above any request struct, and entry num under 1 << 19, the order of a hardware invalidation queue and well beyond any real batch, bounding the per-call loop length.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64289

Affected Products

Linux