---
id: CVE-2026-92505
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/amd: Fix undefined behavior in devid_write debugfs function

  When for_each_pci_segment() loop completes without finding a matching
  segment, the pci_seg pointer is…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  iommu/amd: Fix undefined behavior in devid_write debugfs function

  When for_each_pci_segment() loop completes without finding a matching
  segment, the pci_seg pointer is…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 2e98940f123d9c69d4759078aea9a536244c98d3 <
    8aabe0fba01486b5d893e708b05a8fa7f1b7efbb
  - >-
    Linux >= 2e98940f123d9c69d4759078aea9a536244c98d3 <
    99d42aef089a07cfb1d404a7227ac9dc7628b497
  - >-
    Linux >= 2e98940f123d9c69d4759078aea9a536244c98d3 <
    843e149989665f8309ad2efe6048dc76591e1f94
  - Linux 6.17
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:53.077'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92505'
references:
  - url: 'https://git.kernel.org/stable/c/843e149989665f8309ad2efe6048dc76591e1f94'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8aabe0fba01486b5d893e708b05a8fa7f1b7efbb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/99d42aef089a07cfb1d404a7227ac9dc7628b497'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.781Z'
epss: 0.00206
epssPercentile: 0.09488
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

iommu/amd: Fix undefined behavior in devid_write debugfs function

When for_each_pci_segment() loop completes without finding a matching
segment, the pci_seg pointer is not NULL but points to an invalid memory
location (the list head). Accessing pci_seg->id after the loop causes
undefined behavior.

Fix this by handling the successful case inside the loop and returning
-EINVAL after the loop if no matching segment is found.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
