In the Linux kernel, the following vulnerability has been resolved:
iommu/amd: Bounds-check devid in __rlookup_amd_iommu()
iommu_device_register() walks every device on the PCI bus via bus_for_each_dev() and calls amd_iommu_probe_device() for each. The inlined check_device() path computes the device's sbdf, calls rlookup_amd_iommu() to find the owning IOMMU, and only afterwards verifies devid <= pci_seg->last_bdf. __rlookup_amd_iommu() indexes rlookup_table[devid] with no bounds check of its own, so for a PCI device whose BDF is not described by the IVRS, the lookup reads past the end of the allocation before the caller's bounds check can run.
This was harmless before commit e874c666b15b ("iommu/amd: Change rlookup, irq_lookup, and alias to use kvalloc()"): the table was a zeroed page-order allocation, so the over-read returned NULL and the caller's NULL check skipped the device. After that commit the table is a tight kvcalloc() and the over-read returns adjacent slab contents, which check_device() then dereferences as a struct amd_iommu *, causing a boot-time GPF.
Seen on Google Compute Engine ct6e VMs, where the virtualized IVRS describes only the four TPU endpoints 00:04.0-07.0; the gVNIC at 00:08.0 (devid 0x40) indexes 56 bytes past the 456-byte allocation, into the adjacent kmalloc-512 slab object:
pci 0000:00:04.0: Adding to iommu group 0 pci 0000:00:05.0: Adding to iommu group 1 pci 0000:00:06.0: Adding to iommu group 2 pci 0000:00:07.0: Adding to iommu group 3 Oops: general protection fault, probably for non-canonical address 0x3a64695f78746382: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.18.22 #1 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/06/2025 RIP: 0010:amd_iommu_probe_device+0x54/0x3a0 Call Trace: __iommu_probe_device+0x107/0x520 probe_iommu_group+0x29/0x50 bus_for_each_dev+0x7e/0xe0 iommu_device_register+0xc9/0x240 iommu_go_to_state+0x9c0/0x1c60 amd_iommu_init+0x14/0x40 pci_iommu_init+0x16/0x60 do_one_initcall+0x47/0x2f0
Guard the array access in __rlookup_amd_iommu(). With the fix applied on 6.18.22, the gVNIC at 00:08.0 is skipped cleanly and the VM boots.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-tools-develUpgrade kernel6.18-debuginfoUpgrade kernel6.18-headersUpgrade kernel6.18-develUpgrade perf6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64Upgrade python3-perf6.18-debuginfoUpgrade bpftool6.18-debuginfoUpgrade kernel-livepatch-6.18.33-63.124Upgrade kernel6.18-tools-debuginfoUpgrade python3-perf6.18Upgrade kernel6.18-modules-extraUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-modules-extra-commonUpgrade bpftool6.18Upgrade kernel6.18Upgrade kernel6.18-toolsUpgrade perf6.18 | Jul 13, 2026 | Jun 26, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 26, 2026 |
| Ubuntu | — | Upgrade linux-image-7.0.0-1008-gcp-64kUpgrade linux-image-7.0.0-1009-oemUpgrade linux-image-aws-7.0Upgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-generic-64k-7.0Upgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-1008-gcpUpgrade linux-image-oracle-7.0Upgrade linux-image-genericUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-gke-7.0Upgrade linux-image-ibmUpgrade linux-image-raspiUpgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-gkeUpgrade linux-image-nvidia-bosUpgrade linux-image-azureUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-aws-64k-7.0Upgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-ibm-7.0Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-aws-64kUpgrade linux-image-oem-24.04Upgrade linux-image-gcp-7.0Upgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-7.0.0-28-generic-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-oem-26.04Upgrade linux-image-nvidiaUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1010-azureUpgrade linux-image-generic-64kUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-virtual-hwe-26.04Upgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-gke-64k-7.0Upgrade linux-image-realtime-7.0Upgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-azure-fde-7.0Upgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-raspi-7.0Upgrade linux-image-gcp-64kUpgrade linux-image-virtualUpgrade linux-image-virtual-7.0Upgrade linux-image-oem-7.0Upgrade linux-image-generic-hwe-26.04Upgrade linux-image-azure-7.0Upgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-7.0.0-28-realtimeUpgrade linux-image-awsUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-realtime-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-7.0.0-28-realtime-64kUpgrade linux-image-raspi-realtimeUpgrade linux-image-oracleUpgrade linux-image-gke-64kUpgrade linux-image-azure-fdeUpgrade linux-image-generic-7.0Upgrade linux-image-7.0.0-1003-gke-64kUpgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-realtimeUpgrade linux-image-oem-26.04aUpgrade linux-image-gke-hwe-26.04Upgrade linux-image-nvidia-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-realtime-64k-7.0Upgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04cUpgrade linux-image-nvidia-7.0Upgrade linux-image-7.0.0-1014-azureUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-7.0.0-1003-gkeUpgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-28-genericUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-7.0.0-1011-gcp-64k | Jul 20, 2026 | Jun 26, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub