GPU VulnDB

Database/Control plane, storage & DevOps

Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): MULTI-TENANT ISOLATION: The AMD IOMMU driver looked up

CVE-2026-53283Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: The AMD IOMMU driver looked up device IDs without bounds-checking them, so a device ID outside the expected range indexes past the array. Device enumeration walks every device on the PCI bus, and on a dense GPU node that bus is crowded - many accelerators, switches, NICs and bridges. An out-of-bounds read in the IOMMU's device lookup is a kernel memory-safety issue in the component enforcing DMA isolation.

Who can reach it

Local, triggered during IOMMU device registration and lookup. Influenced by what is on the PCI bus, so a malicious or malfunctioning device - or a device presented by a compromised BMC - can reach it.

What to do

Fixed in the Linux kernel. Distro kernel update plus a node reboot; no firmware step.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.