GPU VulnDB

Database/Kernel, userspace & hypervisor

powerpc/iommu: TCE IOBA range check ignores npages, allowing out-of-range table access

UnscoredCVE-2026-98282Kernel, userspace & hypervisorcurated

Impact

iommu_tce_check_ioba(), the unified IOBA validator for both KVM and VFIO on powerpc, hardcodes a page count of 1 and ignores the caller's npages. H_STUFF_TCE and H_PUT_TCE_INDIRECT legitimately pass npages > 1, so a guest or a VFIO user can submit a range that starts in bounds and runs past the end of the TCE table, with no overflow check on the arithmetic. That is a guest-controlled out-of-bounds access against host IOMMU translation state - the boundary that is supposed to keep a device-assigned VM from reaching other memory. Relevant only to POWER hosts doing KVM or VFIO device passthrough; x86 and arm64 accelerator nodes are unaffected.

Who can reach it

A KVM guest issuing TCE hypercalls, or a local user with VFIO access to a passed-through device, on a powerpc host. Authenticated access to the guest or the VFIO device is required.

What to do

Apply the stable fix that accounts for npages, checks for arithmetic overflow and validates the full requested range against the table size. Kernel update plus host reboot, so drain guests and GPU work from the node. No CVSS score or vendor advisory in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.