« Volver al listado

CVE-2026-98003

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: Do not reallocate GA log buffers on resume

Commit c5e1a1eb9279 ("iommu/amd: Simplify and Consolidate Virtual APIC (AVIC) Enablement") moved the GA log allocation from iommu_init_pci() to enable_iommus_vapic(), which is called on every resume.

iommu_init_ga_log() assigns iommu->ga_log and iommu->ga_log_tail unconditionally. Each resume therefore replaces the boot-time pointers and leaks both old allocations. The function also uses GFP_KERNEL from a syscore resume callback, where interrupts are disabled and the non-boot CPUs are offline.

Leer descripción completaMostrar menos

Return early if both buffers are already allocated. Clear the pointers in free_ga_log() so a partial allocation failure cannot leave ga_log dangling.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98003",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c5e1a1eb9279fdb28d47ca2a4493a4c53b7d6a0b",
              "lessThan": "94458b80d3b203c1c9e2c98aa7319b7713e006c0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c5e1a1eb9279fdb28d47ca2a4493a4c53b7d6a0b",
              "lessThan": "b6be275d19cee01f8f1f08a2ff18337103d05d40",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c5e1a1eb9279fdb28d47ca2a4493a4c53b7d6a0b",
              "lessThan": "00a7dd64888d6dd72110b40e2824a088cf7b7386",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iommu/amd/init.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iommu/amd/init.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:28.533",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00a7dd64888d6dd72110b40e2824a088cf7b7386",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/94458b80d3b203c1c9e2c98aa7319b7713e006c0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6be275d19cee01f8f1f08a2ff18337103d05d40",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Do not reallocate GA log buffers on resume\n\nCommit c5e1a1eb9279 (\"iommu/amd: Simplify and Consolidate Virtual APIC\n(AVIC) Enablement\") moved the GA log allocation from iommu_init_pci()\nto enable_iommus_vapic(), which is called on every resume.\n\niommu_init_ga_log() assigns iommu->ga_log and iommu->ga_log_tail\nunconditionally. Each resume therefore replaces the boot-time pointers\nand leaks both old allocations. The function also uses GFP_KERNEL from a\nsyscore resume callback, where interrupts are disabled and the non-boot\nCPUs are offline.\n\nReturn early if both buffers are already allocated. Clear the pointers\nin free_ga_log() so a partial allocation failure cannot leave ga_log\ndangling."
    }
  ],
  "lastModified": "2026-09-25T11:17:28.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}