Database/Control plane, storage & DevOps
Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): The AMD IOMMU driver looked up device IDs without
Impact
The AMD IOMMU driver looked up device IDs without bounds-checking them, so a device ID outside the expected range indexes past the array. Device enumeration walks every device on the PCI bus, and on a dense GPU node that bus is crowded - many accelerators, switches, NICs and bridges. An out-of-bounds read in the IOMMU's device lookup is a kernel memory-safety issue in the component enforcing DMA isolation.
Who can reach it
Local, triggered during IOMMU device registration and lookup. Influenced by what is on the PCI bus, so a malicious or malfunctioning device - or a device presented by a compromised BMC - can reach it.
What to do
Fixed in the Linux kernel. Distro kernel update plus a node reboot; no firmware step.
References
Related entries
- Linuxfabrik monitoring plugins: sudo-authorized checks read arbitrary root-readable files via --testCVE-2026-73974 · Linuxfabrik Monitoring Plugins / linuxfabrik-lib (lib.lftest.test --test path handling)Medium
- community.general ipa_getkeytab: IPA/LDAP bind password written to logs and exposed in the process listCVE-2026-80158 · Ansible community.general ipa_getkeytab module (bind_pw not declared no_log)Medium
- Harbor (audit log redaction, LDAP password and OIDC client secret): CREDENTIAL DISCLOSURE VIA THE AUDIT TRAIL: HarborNCVD-2026-058-harbor-audit-log-redaction-ldap · Harbor (audit log redaction, LDAP password and OIDC client secret)Medium
- Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attackerCVE-2023-6571 · Kubeflow (central dashboard, reflected cross-site scripting)Medium
- GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictionsCVE-2026-12910 · GitLab CE/EE (SAML SSO sign-in enforcement)Medium
- Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by adminsCVE-2026-13720 · Grafana dashboard API (grafana.app/managedBy provisioning annotations)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.