CVE-2026-64292

Source
https://cve.org/CVERecord?id=CVE-2026-64292
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64292.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64292
Downstream
Published
2026-07-25T08:49:31.325Z
Modified
2026-07-27T04:03:21.192897038Z
Summary
iommufd: Move vevent memory allocation outside spinlock
Details

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Move vevent memory allocation outside spinlock

The veventq memory allocation happens inside the spinlock. Given its depth is decided by the user space, this leaves a vulnerability, where userspace can allocate large queues to exhaust atomic memory reserves.

Move the allocation outside the spinlock and use GFPNOWAIT, which can fail fast under memory pressure without dipping into the GFPATOMIC reserves or direct-reclaiming from the threaded IRQ handler. On allocation failure, queue the losteventsheader (so userspace learns of the drop) and return -ENOMEM so the caller learns of the kernel-side memory pressure.

This is intentionally distinct from the queue-overflow path, which also queues the losteventsheader but returns 0: a full queue is an expected userspace-pacing condition rather than a kernel error.

A subsequent change will cap the upper bound of the veventq_depth.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64292.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e36ba5ab808ef6237c3148d469c8238674230e2b
Fixed
779480ea79551c31964e74b9aef0e730faa3aa11
Fixed
6c5fc40200cd0a87d66a368eee00df4d1cca946e
Fixed
47443565d10c51366c9382dbc8597cd6c460b8a2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64292.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64292.json"