CVE-2026-64290

Source
https://cve.org/CVERecord?id=CVE-2026-64290
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64290.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64290
Downstream
Related
Published
2026-07-25T08:49:30.049Z
Modified
2026-08-18T03:30:55.740962038Z
Summary
iommufd: Break the loop on failure in iommufd_fault_fops_read()
Details

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Break the loop on failure in iommufdfaultfops_read()

On a copytouser() failure inside the inner listforeachentry, only the inner loop breaks; the outer while re-fetches the just-restored fault group and retries the failing copyto_user() forever, spinning the reader at 100% CPU with fault->mutex held.

Check rc after the inner loop and break the outer while as well.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64290.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
07838f7fd529c8a6de44b601d4b7057e6c8d36ed
Fixed
a38e0714affc5c0bbb40cba5a65d6d32a5e72a71
Fixed
5539da127d03c1f6c2e2a49fdfbe331a0ccbdea8
Fixed
f66c16b175509642ee7082df57c9bf3deaebae1a
Fixed
172fc8b19825a0f5884c38f2289188284e2d45ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64290.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64290.json"