Database/Kernel, userspace & hypervisor
Linux kernel Intel IOMMU: out-of-bounds memset in dmar_latency_disable() corrupts adjacent memory
Impact
The DMAR latency statistics teardown path clears sizeof(*lstat) * DMAR_LATENCY_NUM bytes starting at &lstat[type] instead of a single entry, so any type greater than zero writes zeroes past the end of the allocated array. On a GPU node the Intel IOMMU is the boundary that keeps a passed-through accelerator's DMA inside its assigned domain, so memory corruption in that driver's state is worth taking seriously even when the trigger is administrative. Reachable state is limited: the latency measurement facility is a debugfs-gated diagnostic, not something a tenant workload touches. Expected outcome is kernel memory corruption leading to instability rather than a demonstrated privilege boundary crossing.
Who can reach it
Local, privileged. Requires the ability to toggle the Intel IOMMU latency debugfs interface, which normally means root on the host with debugfs mounted. No tenant-facing path is described in the record.
What to do
Take the stable kernel fix from one of the linked git.kernel.org commits, or the equivalent backport from your distribution. Applying it means booting a new kernel, so each GPU host has to be cordoned, drained of running jobs and rebooted. No fixed release version is stated in the record. If the maintenance window is expensive, note that leaving the IOMMU latency debugfs facility unused avoids the code path entirely.
References
Related entries
- Linux kernel BPF sockmap: unhashed UDP sockets leak socket refcounts, exhausting host memoryCVE-2026-68386 · Linux kernel BPF sockmap (UDP socket refcount on map update)Unscored
- Linux kernel KVM x86 MMU: use-after-free when a vendor module is reloaded after a failed initCVE-2026-68428 · Linux kernel KVM x86 MMU (mmu_destroy_caches)Unscored
- Linux perf/x86/amd/brs - kernel address leakage through Branch Sampling: A user-only branch stack collected via AMDCVE-2026-72237 · Linux perf/x86/amd/brs - kernel address leakage through Branch SamplingUnscored
- Linux BPF verifier: kernel pointers leak through verifier logs for three pseudo ldimm64 sourcesCVE-2026-72402 · Linux kernel BPF verifier (ldimm64 pseudo-pointer masking in verifier logs)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-74353 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Memory is handed to a consumer without beingCVE-2026-74448 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.