PT-2026-64513 · Linux+1 · Linux Kernel+1

CVE-2026-64292

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the iommufd component, memory allocation for veventq occurs inside a spinlock. Because the queue depth is determined by user space, a user can allocate excessively large queues to exhaust atomic memory reserves. To address this, the allocation is moved outside the spinlock using GFP NOWAIT, which allows the system to fail quickly under memory pressure without consuming GFP ATOMIC reserves or performing direct-reclaiming from the threaded IRQ handler. If allocation fails, the system queues the lost events header and returns -ENOMEM to notify the caller of kernel-side memory pressure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64292
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu