Database/Kernel, userspace & hypervisor
powerpc/iommu: TCE IOBA range check ignores npages, allowing out-of-range table access
Impact
iommu_tce_check_ioba(), the unified IOBA validator for both KVM and VFIO on powerpc, hardcodes a page count of 1 and ignores the caller's npages. H_STUFF_TCE and H_PUT_TCE_INDIRECT legitimately pass npages > 1, so a guest or a VFIO user can submit a range that starts in bounds and runs past the end of the TCE table, with no overflow check on the arithmetic. That is a guest-controlled out-of-bounds access against host IOMMU translation state - the boundary that is supposed to keep a device-assigned VM from reaching other memory. Relevant only to POWER hosts doing KVM or VFIO device passthrough; x86 and arm64 accelerator nodes are unaffected.
Who can reach it
A KVM guest issuing TCE hypercalls, or a local user with VFIO access to a passed-through device, on a powerpc host. Authenticated access to the guest or the VFIO device is required.
What to do
Apply the stable fix that accounts for npages, checks for arithmetic overflow and validates the full requested range against the table size. Kernel update plus host reboot, so drain guests and GPU work from the node. No CVSS score or vendor advisory in the record.
References
Related entries
- KVM PPC Book3S HV: use-after-free on nested guest struct during all-LPID tlbie emulationCVE-2026-98283 · Linux kernel KVM PPC Book3S HV (kvmhv_emulate_tlbie_all_lpid)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
- VMware ESXi (OpenSLP): Use-after-free in OpenSLP on port 427 - unauthenticated remote code execution on the hypervisorCVE-2020-3992 · VMware ESXi (OpenSLP)Critical
- Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handlerCVE-2021-47215 · Linux kernel mlx5_core kTLS RX offloadCritical
- Linux kernel (drivers/nvme/host): The NVMe/RDMA initiator destroys the queue pair before the connection manager ID, soCVE-2021-47378 · Linux kernel (drivers/nvme/host)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.