---
id: CVE-2026-98282
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba

  The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
  IOBA parameter checking acro…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba

  The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
  IOBA parameter checking acro…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    98d8dcc4ebd10523507d4478e148809a7771a213
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    9fd9c9bbb05417f468a11fb6d145d7ff61f4a868
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    3776bf56e06980e8a12c8c0565d9e6ac44965f03
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    d6a1779129d936bc1fbab80181165da544eab736
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    d48ceb6e1a6915c7bac4f902554a1047365cdff2
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    0543813753ef5cfbd6fa96694f7acf783fa01af7
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    314091243159f8e3749bc719bb129f423f72fd86
  - >-
    Linux >= b1af23d836f811137d504d14d4cbdd01929dec34 <
    0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71
  - Linux 4.12
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:18.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98282'
references:
  - url: 'https://git.kernel.org/stable/c/0543813753ef5cfbd6fa96694f7acf783fa01af7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/314091243159f8e3749bc719bb129f423f72fd86'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3776bf56e06980e8a12c8c0565d9e6ac44965f03'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/98d8dcc4ebd10523507d4478e148809a7771a213'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9fd9c9bbb05417f468a11fb6d145d7ff61f4a868'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d48ceb6e1a6915c7bac4f902554a1047365cdff2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d6a1779129d936bc1fbab80181165da544eab736'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.420Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba

The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified
IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().
While doing so, the passed in argument npages is ignored and constant
value '1' is used leaving out a possible overflow as the callers can
legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT
cases.

Fix this by accounting for 'npages', checking for arithmetic overflow,
and verifying that the entire requested range (ioba - offset + npages)
does not exceed the table capacity 'size'.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
