Executive brief
A vulnerability in the Linux kernel's I/O Memory Management Unit (IOMMU) subsystem could allow a local user to cause a system crash or freeze. By providing excessively large values during certain hardware communication requests, an attacker can force the system into an infinite loop or trigger a 'soft lockup' that stops the computer from responding. This primarily impacts the availability of the affected server or workstation.
Technical details
A denial-of-service vulnerability exists in iommufd_hwpt_invalidate() due to insufficient validation of user-controlled 'entry_num' and 'entry_len' parameters. An attacker can provide an 'entry_len' exceeding the kernel's internal structure size, causing the copy helper to perform an uninterruptible scan of user memory, or a large 'entry_num' that drives a backend invalidation loop without rescheduling. This can result in the CPU being pinned on non-preemptible kernels, triggering soft-lockup watchdogs. The fix introduces upper bounds for both parameters (PAGE_SIZE for entry_len and 1 << 19 for entry_num) within the ioctl handler.
Affected products
- Linux Linux Kernel 6.8 to 7.1.4, 6.12.96, 6.18.39
Timeline
- 2026-06-03: disclosed: Initial patch authored by Nicolin Chen
- 2026-07-25: advisory: CVE published in NVD dataset
- 2026-07-18: patched: Commits merged into stable branches