Answer in brief
CVE-2026-98282 records a Unknown severity vulnerability in powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b1af23d836f811137d504d14d4cbdd01929dec34 <98d8dcc4ebd10523507d4478e148809a7771a213 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <9fd9c9bbb05417f468a11fb6d145d7ff61f4a868 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <3776bf56e06980e8a12c8c0565d9e6ac44965f03 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <d6a1779129d936bc1fbab80181165da544eab736 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <d48ceb6e1a6915c7bac4f902554a1047365cdff2 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <0543813753ef5cfbd6fa96694f7acf783fa01af7 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <314091243159f8e3749bc719bb129f423f72fd86 || >=b1af23d836f811137d504d14d4cbdd01929dec34 <0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 | 98d8dcc4ebd10523507d4478e148809a7771a213, 9fd9c9bbb05417f468a11fb6d145d7ff61f4a868, 3776bf56e06980e8a12c8c0565d9e6ac44965f03, d6a1779129d936bc1fbab80181165da544eab736, d48ceb6e1a6915c7bac4f902554a1047365cdff2, 0543813753ef5cfbd6fa96694f7acf783fa01af7, 314091243159f8e3749bc719bb129f423f72fd86, 0b271f7d7f5ed45bc498a03ce0aa9cfd8402fc71 |
| Linux/Linuxgeneric | 4.12 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba The commit b1af23d836f8 ("KVM: PPC: iommu: Unify TCE checking") unified IOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba(). While doing so, the passed in argument npages is ignored and constant value '1' is used leaving out a possible overflow as the callers can legitimately be using npages > 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT cases. Fix this by accounting for 'npages', checking for arithmetic overflow, and verifying that the entire requested range (ioba - offset + npages) does not exceed the table capacity 'size'.
Quoted source text, attributed separately from HOL analysis.