Sceawere

Vulnerability Detail

CVE-2026-98282UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Integer Overflow in PowerPC IOMMU

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases. Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T09:18:18.180Z",
  "pubdate": "2026-10-06T09:18:18.180Z",
  "executiveSummary": "The Linux kernel's PowerPC IOMMU subsystem contains an integer overflow vulnerability within the iommu_tce_check_ioba function.\nThis vulnerability arises from improper validation of I/O Bus Address (IOBA) ranges, where the npages parameter is incorrectly ignored in favor of a constant value.\nThe flaw affects systems utilizing KVM and VFIO for IOMMU operations on PowerPC architectures.\nIf exploited, an attacker could bypass bounds checking, leading to memory corruption or arbitrary access to IOMMU table entries.\nThe risk is categorized as high, as it allows potential memory safety violations within the kernel-space handling of TCE (TCE Table Entry) updates.\nExploitation typically requires an attacker to have the ability to interface with the KVM or VFIO subsystem, often necessitating guest-level access in virtualized environments.",
  "technicalDetails": "The root cause of this vulnerability lies in the unification of TCE checking logic via the iommu_tce_check_ioba function, introduced in commit b1af23d836f8. During the unification process, the implementation failed to account for the npages argument, which defines the number of TCE entries to be updated or cleared.\nBy hardcoding the page count to '1', the validation logic fails to correctly calculate the total range of the IOBA (I/O Bus Address) being accessed. Legitimate operations such as H_STUFF_TCE or H_PUT_TCE_INDIRECT frequently request operations involving multiple pages (npages > 1).\nAn attacker can trigger this vulnerability by providing a crafted IOBA and npages value that, while individually appearing valid, results in a calculated memory range that exceeds the table's actual capacity (size). Because the function does not perform arithmetic overflow checks on the expression (ioba - offset + npages), the bounds check logic remains incomplete.\nThe attack flow proceeds as follows: 1) The attacker initiates an H_STUFF_TCE or H_PUT_TCE_INDIRECT hypercall or IOCTL via VFIO. 2) The attacker specifies an npages value that causes the resulting IOBA range to wrap around or extend beyond the designated IOMMU table boundaries. 3) The iommu_tce_check_ioba function evaluates the range using the faulty logic, erroneously passing the bounds check. 4) The kernel subsequently operates on memory outside the intended IOMMU table, leading to potential out-of-bounds reads or writes to sensitive kernel memory structures.\nThis vulnerability is critical because it resides in the core kernel interface for memory management and virtualization. Successful exploitation could lead to kernel memory corruption, leading to a system crash (Denial of Service) or potential escalation of privileges if an attacker can manipulate IOMMU mappings to gain access to unauthorized memory regions on the host or other guests."
}
CVE-2026-98282: Integer Overflow in PowerPC IOMMU (HIGH Severity, CVSS: 8.8) | Sceawere