Executive brief
A vulnerability was identified in the Linux kernel's AMD IOMMU driver that could allow a local administrator to trigger an out-of-bounds memory access. The issue exists in the debugfs interface, which is typically used for system debugging and diagnostics. While existing safeguards limited the practical impact, an exploit could potentially lead to system instability or a crash.
Technical details
A vulnerability in the AMD IOMMU debugfs implementation (drivers/iommu/amd/debugfs.c) arises because the variables dbg_mmio_offset and dbg_cap_offset are declared as signed integers but populated via kstrtou32_from_user(). A local attacker with root privileges (required to access debugfs) could provide a large input value that wraps to a negative integer, potentially bypassing bounds checks that only verified the upper limit. This could lead to out-of-bounds memory access in iommu_mmio_write() and iommu_capability_write(). The issue has been resolved by using kstrtos32_from_user() and explicitly checking for negative values. Fixes are available in stable kernel branches 6.18.34, 7.0.11, and 7.1+.
Affected products
- Linux Linux Kernel 6.17 to 6.18.33, 7.0.0 to 7.0.10
Timeline
- 2026-04-10: other: Patch authored
- 2026-07-19: disclosed: CVE published