In the Linux kernel, the following vulnerability has been resolved:
iommufd: Set veventq_depth upper bound
iommufdveventqalloc() accepts any !0 veventqdepth from userspace, with an upper bound at U32MAX.
This leaves a vulnerability where userspace can allocate excessively large queues to exhaust kernel memory reserves.
Cap the veventq_depth (maximum number of entries) to 1 << 19, matching the maximum number of entries in the SMMUv3 EVTQ (the largest use case today).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64291.json",
"cna_assigner": "Linux"
}