PT-2026-98665 · Linux · Linux

CVE-2026-98002

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Fix ineffective error check in nested domain allocation
amd iommu pdom id alloc() returns an int: a domain ID on success, or the negative errno from ida alloc range() when the ID space is exhausted or memory is short. amd iommu alloc domain nested() stores that return value in gdom info->hdom id, which is a u32, and only then tests it:
gdom info->hdom id = amd iommu pdom id alloc();
if (gdom info->hdom id <= 0) {
The assignment discards the sign, so -ENOSPC becomes 0xffffffe4 and the test never fires. The nested domain is then set up with a host domain ID that was never allocated, instead of the allocation failing with -ENOSPC.
Keep the value in an int, test it there, and store it only once it is known to be valid, which is what the other amd iommu pdom id alloc() callers already do.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98002

Affected Products

Linux