CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081034-CVE-2026-68324-6e93@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()

dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].

When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.

Fix by using sizeof(*lstat) to clear only the target entry.

The Linux kernel CVE team has assigned CVE-2026-68324 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.14 with commit 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e and fixed in 6.6.148 with commit 3078d82e7fe9048a2b90a992e71af7cd7ef881fa
	Issue introduced in 5.14 with commit 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e and fixed in 6.12.101 with commit 866a35735e56b9dc81cbc33899255134adf6d8b3
	Issue introduced in 5.14 with commit 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e and fixed in 6.18.42 with commit d06fea9b85f038690f55e72fe0c45e113715a85a
	Issue introduced in 5.14 with commit 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e and fixed in 7.1.6 with commit 0e28ca1c3204b51068579defc904a0dfba5e5c57
	Issue introduced in 5.14 with commit 55ee5e67a59a1b6f388d7a1c7b24022145f47a3e and fixed in 7.2-rc5 with commit 754f8efe45f87e3a9c6871b645b2f9d46d1b407b

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-68324
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/iommu/intel/perf.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/3078d82e7fe9048a2b90a992e71af7cd7ef881fa
	https://git.kernel.org/stable/c/866a35735e56b9dc81cbc33899255134adf6d8b3
	https://git.kernel.org/stable/c/d06fea9b85f038690f55e72fe0c45e113715a85a
	https://git.kernel.org/stable/c/0e28ca1c3204b51068579defc904a0dfba5e5c57
	https://git.kernel.org/stable/c/754f8efe45f87e3a9c6871b645b2f9d46d1b407b
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.