Medium severity5.5NVD Advisory· Published Jul 25, 2026· Updated Aug 17, 2026
CVE-2026-64291
CVE-2026-64291
Description
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Set veventq_depth upper bound
iommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with an upper bound at U32_MAX.
This leaves a vulnerability where userspace can allocate excessively large queues to exhaust kernel memory reserves.
Cap the veventq_depth (maximum number of entries) to 1 << 19, matching the maximum number of entries in the SMMUv3 EVTQ (the largest use case today).
Affected products
6- osv-coords4 versionspkg:linux/kernelpkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootc
>= 6.15.0, < 6.18.39+ 3 more
- (no CPE)range: >= 6.15.0, < 6.18.39
- (no CPE)range: < 7.1.7-1.1
- (no CPE)range: < 6.18.44-r0
- (no CPE)range: < 6.18.44-r0
Patches
Vulnerability mechanics
References
3News mentions
2- Linux Kernel: 25 Vulnerabilities Across Subsystems Disclosed Together, Patched in Single UpdateVypr Intelligence · Jul 28, 2026
- Linux Kernel: 25 Vulnerabilities Across Subsystems Disclosed TogetherVypr Intelligence · Jul 26, 2026