Junglewise Threat Intelligence

CVE-2025-38688: Linux Kernel integer overflow in iommufd IOVA allocation

CVE-2025-38688 · Severity: high · CVSS 8.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management component (iommufd) could allow a local user to corrupt memory mappings. By triggering an integer overflow during memory allocation, an attacker could create overlapping memory regions that should be isolated. This could lead to unauthorized access to sensitive data or system instability.

Technical details

An integer overflow vulnerability exists in the iommufd component of the Linux kernel during IO Virtual Address (IOVA) allocation. When a candidate range is close to ULONG_MAX, the ALIGN() macro can wrap around, resulting in a corrupted IOVA. This flaw allows a local attacker with userspace access to create memory mappings that overlap with other existing mappings or reserved ranges. The fix involves replacing the ALIGN() macro with check_add_overflow() to safely handle potential wraps. Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, 6.15.y, and 6.16.y.

Affected products

  • Linux Linux Kernel 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-09-04: advisory: Vulnerability published in NVD

References

Related threats