What is CVE-2026-64291?
This vulnerability in the Linux kernel's iommufd subsystem allows userspace to specify an excessively large `veventq_depth`, lacking a proper upper bound enforcement. This can lead to memory exhaustion and potential Denial of Service (DoS). Systems affected should apply patches to mitigate this issue.
Azərbaycanca: Linux Kernel-də iommufd alt sistemində aşkarlanan bu boşluq (CVE-2026-64291) `veventq_depth` parametrinin yuxarı həddinin düzgün təyin edilməməsi ilə bağlıdır. İstifadəçi sahəsindən göndərilən həddən artıq böyük dəyər nəticəsində yaddaş ehtiyatlarının tükənməsi (memory exhaustion) baş verə bilər. Təsirə məruz qalan sistemlərdə yamaq tətbiq edilənə qədər potensial DoS hücumlarına qarşı tədbirlər görülməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which subsystem of the Linux Kernel was CVE-2026-64291 discovered?
This vulnerability was discovered in the iommufd subsystem of the Linux Kernel.
What can an attacker achieve by exploiting this vulnerability?
An attacker can cause memory exhaustion by sending an excessively large value for the `veventq_depth` parameter, potentially leading to DoS attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.