CVE-2026-64291
iommufd: Set veventq_depth upper bound
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: iommufd: Set veventq_depth upper bound iommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with an upper bound at U32_MAX. This leaves a vulnerability where userspace can allocate excessively large queues to exhaust kernel memory reserves. Cap the veventq_depth (maximum number of entries) to 1 << 19, matching the maximum number of entries in the SMMUv3 EVTQ (the largest use case today).
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
e36ba5ab808ef6237c3148d469c8238674230e2b < f565297edf316016be4a1a9e2eb9f39359313f43 e36ba5ab808ef6237c3148d469c8238674230e2b < e7b5e55652746b1221b9c10ff80eae8a154101ba e36ba5ab808ef6237c3148d469c8238674230e2b < 6ebf2eb46fbd5b40393ff8fbb847ba96925beaff
Linux / Linux
6.15