PT-2026-98665 · Linux · Linux

CVE-2026-98002

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix ineffective error check in nested domain allocation
amd iommu pdom id alloc() returns an int: a domain ID on success, or the negative errno from ida alloc range() when the ID space is exhausted or memory is short. amd iommu alloc domain nested() stores that return value in gdom info->hdom id, which is a u32, and only then tests it:
gdom info->hdom id = amd iommu pdom id alloc();
if (gdom info->hdom id <= 0) {
The assignment discards the sign, so -ENOSPC becomes 0xffffffe4 and the test never fires. The nested domain is then set up with a host domain ID that was never allocated, instead of the allocation failing with -ENOSPC.
Keep the value in an int, test it there, and store it only once it is known to be valid, which is what the other amd iommu pdom id alloc() callers already do.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98002

Produtos afetados

Linux