GHSA-hrwq-83vm-hr68unknown

In the Linux kernel, the following vulnerability has been resolved: iommu/intel: Fix out-of...

Published
August 10, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()

dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type].

When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory.

Fix by using sizeof(*lstat) to clear only the target entry.

🔗 References (9)