VYPR
Medium severity5.5NVD Advisory· Published Jul 25, 2026· Updated Aug 17, 2026

CVE-2026-64291

CVE-2026-64291

Description

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Set veventq_depth upper bound

iommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with an upper bound at U32_MAX.

This leaves a vulnerability where userspace can allocate excessively large queues to exhaust kernel memory reserves.

Cap the veventq_depth (maximum number of entries) to 1 << 19, matching the maximum number of entries in the SMMUv3 EVTQ (the largest use case today).

Affected products

6

Patches

Vulnerability mechanics

References

3

News mentions

2