PT-2026-98665 · Linux · Linux
CVE-2026-98002
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix ineffective error check in nested domain allocation
amd iommu pdom id alloc() returns an int: a domain ID on success, or the
negative errno from ida alloc range() when the ID space is exhausted or
memory is short. amd iommu alloc domain nested() stores that return value
in gdom info->hdom id, which is a u32, and only then tests it:
gdom info->hdom id = amd iommu pdom id alloc();
if (gdom info->hdom id <= 0) {The assignment discards the sign, so -ENOSPC becomes 0xffffffe4 and the
test never fires. The nested domain is then set up with a host domain ID
that was never allocated, instead of the allocation failing with -ENOSPC.
Keep the value in an int, test it there, and store it only once it is
known to be valid, which is what the other amd iommu pdom id alloc()
callers already do.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux