GHSA-6gx3-fvx8-mx4pMediumCVSS 5.5

In the Linux kernel, the following vulnerability has been resolved: iommufd: Set veventq_depth...

Published
July 25, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Set veventq_depth upper bound

iommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with an upper bound at U32_MAX.

This leaves a vulnerability where userspace can allocate excessively large queues to exhaust kernel memory reserves.

Cap the veventq_depth (maximum number of entries) to 1 << 19, matching the maximum number of entries in the SMMUv3 EVTQ (the largest use case today).

🔗 References (5)