CVE-2026-98282

Source
https://cve.org/CVERecord?id=CVE-2026-98282
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98282.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98282
Downstream
Published
2026-10-06T08:45:43Z
Modified
2026-10-07T02:47:26Z
Summary
powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
Details

In the Linux kernel, the following vulnerability has been resolved:

powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba

The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases.

Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98282.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b1af23d836f811137d504d14d4cbdd01929dec34
Fixed
98d8dcc4ebd10523507d4478e148809a7771a213
Fixed
9fd9c9bbb05417f468a11fb6d145d7ff61f4a868
Fixed
3776bf56e06980e8a12c8c0565d9e6ac44965f03
Fixed
d6a1779129d936bc1fbab80181165da544eab736
Fixed
d48ceb6e1a6915c7bac4f902554a1047365cdff2
Fixed
0543813753ef5cfbd6fa96694f7acf783fa01af7
Fixed
314091243159f8e3749bc719bb129f423f72fd86
Fixed
0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98282.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98282.json"