In the Linux kernel, the following vulnerability has been resolved:
iommu: Don't reserve 0-length IOVA region
When the bootloader/firmware doesn't setup the framebuffers, their address and size are 0 in "iommu-addresses" property. If IOVA region is reserved with 0 length, then it ends up corrupting the IOVA rbtree with an entry which has pfn_hi < pfn_lo. If we intend to use display driver in kernel without framebuffer then it's causing the display IOMMU mappings to fail as entire valid IOVA space is reserved when address and length are passed as 0. An ideal solution would be firmware removing the "iommu-addresses" property and corresponding "memory-region" if display is not present. But the kernel should be able to handle this by checking for size of IOVA region and skipping the IOVA reservation if size is 0. Also, add a warning if firmware is requesting 0-length IOVA region reservation.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | No solution existsUpgrade kernel-rtUpgrade kernel | Dec 5, 2024 | Feb 23, 2024 |
| Ubuntu | — | Upgrade linux-image-6.5.0-1021-nvidia-64kUpgrade linux-image-oracle-64kUpgrade linux-image-6.5.0-41-genericUpgrade linux-image-oem-22.04cUpgrade linux-image-generic-lpaeUpgrade linux-image-6.5.0-1015-starfiveUpgrade linux-image-6.5.0-1022-azure-fdeUpgrade linux-image-6.5.0-1022-azureUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.5.0-41-lowlatency-64kUpgrade linux-image-lowlatencyUpgrade linux-image-gcpUpgrade linux-image-6.5.0-41-lowlatencyUpgrade linux-image-genericUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-oem-22.04Upgrade linux-image-generic-64kUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-6.5.0-1021-nvidiaUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-6.5.0-41-generic-64kUpgrade linux-image-oem-22.04dUpgrade linux-image-6.5.0-1022-gcpUpgrade linux-image-virtualUpgrade linux-image-lowlatency-64kUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-oem-22.04aUpgrade linux-image-awsUpgrade linux-image-6.5.0-1017-laptopUpgrade linux-image-oem-22.04bUpgrade linux-image-nvidia-64k-6.5Upgrade linux-image-azureUpgrade linux-image-nvidia-6.5Upgrade linux-image-kvmUpgrade linux-image-azure-fdeUpgrade linux-image-laptop-23.10Upgrade linux-image-starfiveUpgrade linux-image-6.5.0-1018-raspiUpgrade linux-image-6.5.0-1021-awsUpgrade linux-image-oracleUpgrade linux-image-raspiUpgrade linux-image-raspi-nolpaeUpgrade linux-image-6.5.0-1024-oracle-64kUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-6.5.0-1024-oemUpgrade linux-image-6.5.0-1024-oracleUpgrade linux-image-lowlatency-hwe-22.04 | May 17, 2024 | Feb 23, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub