CVE-2026-64289
Last modified
CVE-2026-64289 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iommufd: Set upper bounds on cache invalidation entry_num and entry_len iommufd_hwpt_invalidate() takes a user-controlled entry_num and entry_len, each bounded only by U32_MAX. An entry_len beyond the kernel's struct size makes the copy helper verify the extra bytes are zero, scanning that excess in one uninterruptible pass; a multi-gigabyte value over zeroed user memory trips the soft-lockup watchdog. A large entry_num is the other half, driving the backend invalidation loop with no reschedule. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: iommufd: Set upper bounds on cache invalidation entry_num and entry_len iommufd_hwpt_invalidate() takes a user-controlled entry_num and entry_len, each bounded only by U32_MAX. An entry_len beyond the kernel's struct size makes the copy helper verify the extra bytes are zero, scanning that excess in one uninterruptible pass; a multi-gigabyte value over zeroed user memory trips the soft-lockup watchdog. A large entry_num is the other half, driving the backend invalidation loop with no reschedule. The VT-d nested handler, for one, copies each entry and flushes caches per iteration, pinning the CPU on a non-preemptible kernel. Cap both in the ioctl. entry_len is held under PAGE_SIZE, above any request struct, and entry_num under 1 << 19, the order of a hardware invalidation queue and well beyond any real batch, bounding the per-call loop length.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 8c6eabae3807e048b9f17733af5e20500fbf858c, < d2bd041e0efaf7d81789779b135279d18b33d6d5; >= 8c6eabae3807e048b9f17733af5e20500fbf858c, < 32ca4aed2a66205b072fcfecabe220289a8149ff; >= 8c6eabae3807e048b9f17733af5e20500fbf858c, < 2c6381d90898089287e0a358f06f89f6b4b389f2; >= 8c6eabae3807e048b9f17733af5e20500fbf858c, < 4d70986002f2f3eaaed89124fb2522bded38b016 |
| Linux | Linux | 6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64289?
How severe is CVE-2026-64289?
How do I fix CVE-2026-64289?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64283In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64284In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64285In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64286In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2026-64287In the Linux kernel, the following vulnerability has been re…8.2
- CVE-2026-64288In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6429When asked to both use a `.netrc` file for credentials and t…5.3
- CVE-2026-64290In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-64291In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-64292In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-64293In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64294In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2026-64289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
