CVE-2026-68324

Unknown

Last modified

CVE-2026-68324 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type]. When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory. Fix by using sizeof(*lstat) to clear only the target entry..

Description

In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type]. When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory. Fix by using sizeof(*lstat) to clear only the target entry.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e, < 3078d82e7fe9048a2b90a992e71af7cd7ef881fa; >= 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e, < 866a35735e56b9dc81cbc33899255134adf6d8b3; >= 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e, < d06fea9b85f038690f55e72fe0c45e113715a85a; >= 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e, < 0e28ca1c3204b51068579defc904a0dfba5e5c57; >= 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e, < 754f8efe45f87e3a9c6871b645b2f9d46d1b407b
LinuxLinux5.14

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68324?
In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type]. When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory. Fix by using sizeof(*lstat) to clear only the target entry.
How severe is CVE-2026-68324?
Severity scoring for CVE-2026-68324 is pending analysis.
How do I fix CVE-2026-68324?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68324?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST