CVE-2026-64291: iommufd: Set veventq_depth upper bound
In the Linux kernel, the following vulnerability has been resolved:
iommufd: Set veventqdepth upper bound
iommufdveventqalloc() accepts any !0 veventqdepth from userspace, with an upper bound at U32MAX.
This leaves a vulnerability where userspace can allocate excessively large queues to exhaust kernel memory reserves.
Cap the veventqdepth (maximum number of entries) to 1 << 19, matching the maximum number of entries in the SMMUv3 EVTQ (the largest use case today).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Cap userspace-provided veventq_depth (maximum number of entries) to 1 << 19 to prevent excessive allocation that can exhaust kernel memory reserves.
iommufd (iommufd_veventq_alloc / veventq_depth) veventq_depth upper bound = 1 << 19