{"id":"AZL-106383","summary":"CVE-2026-98282 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba\n\nThe commit b1af23d836f8 (\"KVM: PPC: iommu: Unify TCE checking\") unified\nIOBA parameter checking across KVM and VFIO into iommu_tce_check_ioba().\nWhile doing so, the passed in argument npages is ignored and constant\nvalue '1' is used leaving out a possible overflow as the callers can\nlegitimately be using npages \u003e 1 for H_STUFF_TCE or H_PUT_TCE_INDIRECT\ncases.\n\nFix this by accounting for 'npages', checking for arithmetic overflow,\nand verifying that the entire requested range (ioba - offset + npages)\ndoes not exceed the table capacity 'size'.","modified":"2026-10-07T14:17:06.230123095Z","published":"2026-10-06T09:18:18Z","upstream":["CVE-2026-98282"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98282"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106383.json"}}],"schema_version":"1.9.0"}