What is CVE-2026-64289?
CVE-2026-64289 is a vulnerability in the iommufd driver of the Linux kernel. It stems from missing upper bounds on user-controlled entry_num and entry_len parameters, allowing values up to U32_MAX. Affected systems should apply the kernel patch that sets the required bounds on cache invalidation entries.
Azərbaycanca: CVE-2026-64289 Linux kernel-da IOMMUFD sürücüsündə aşkar edilmiş boşluqdur. İstifadəçi tərəfindən idarə olunan entry_num və entry_len parametrləri üçün yuxarı həddin olmaması (U32_MAX-a qədər) potensial təhlükəsizlik riskinə səbəb ola bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which component of the Linux kernel is affected by CVE-2026-64289?
CVE-2026-64289 affects the iommufd driver in the Linux kernel.
What is the root cause of the CVE-2026-64289 vulnerability?
The vulnerability stems from missing upper bounds on user-controlled entry_num and entry_len parameters.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.