Sceawere
Vulnerability Detail
CVE-2026-98282UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Integer Overflow in PowerPC IOMMU
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases. Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-06T09:18:18.180Z",
"pubdate": "2026-10-06T09:18:18.180Z",
"executiveSummary": "The Linux kernel's PowerPC IOMMU subsystem contains an integer overflow vulnerability within the iommu_tce_check_ioba function.\nThis vulnerability arises from improper validation of I/O Bus Address (IOBA) ranges, where the npages parameter is incorrectly ignored in favor of a constant value.\nThe flaw affects systems utilizing KVM and VFIO for IOMMU operations on PowerPC architectures.\nIf exploited, an attacker could bypass bounds checking, leading to memory corruption or arbitrary access to IOMMU table entries.\nThe risk is categorized as high, as it allows potential memory safety violations within the kernel-space handling of TCE (TCE Table Entry) updates.\nExploitation typically requires an attacker to have the ability to interface with the KVM or VFIO subsystem, often necessitating guest-level access in virtualized environments.",
"technicalDetails": "The root cause of this vulnerability lies in the unification of TCE checking logic via the iommu_tce_check_ioba function, introduced in commit b1af23d836f8. During the unification process, the implementation failed to account for the npages argument, which defines the number of TCE entries to be updated or cleared.\nBy hardcoding the page count to '1', the validation logic fails to correctly calculate the total range of the IOBA (I/O Bus Address) being accessed. Legitimate operations such as H_STUFF_TCE or H_PUT_TCE_INDIRECT frequently request operations involving multiple pages (npages > 1).\nAn attacker can trigger this vulnerability by providing a crafted IOBA and npages value that, while individually appearing valid, results in a calculated memory range that exceeds the table's actual capacity (size). Because the function does not perform arithmetic overflow checks on the expression (ioba - offset + npages), the bounds check logic remains incomplete.\nThe attack flow proceeds as follows: 1) The attacker initiates an H_STUFF_TCE or H_PUT_TCE_INDIRECT hypercall or IOCTL via VFIO. 2) The attacker specifies an npages value that causes the resulting IOBA range to wrap around or extend beyond the designated IOMMU table boundaries. 3) The iommu_tce_check_ioba function evaluates the range using the faulty logic, erroneously passing the bounds check. 4) The kernel subsequently operates on memory outside the intended IOMMU table, leading to potential out-of-bounds reads or writes to sensitive kernel memory structures.\nThis vulnerability is critical because it resides in the core kernel interface for memory management and virtualization. Successful exploitation could lead to kernel memory corruption, leading to a system crash (Denial of Service) or potential escalation of privileges if an attacker can manipulate IOMMU mappings to gain access to unauthorized memory regions on the host or other guests."
}