{"id":"CVE-2026-92505","summary":"iommu/amd: Fix undefined behavior in devid_write debugfs function","details":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Fix undefined behavior in devid_write debugfs function\n\nWhen for_each_pci_segment() loop completes without finding a matching\nsegment, the pci_seg pointer is not NULL but points to an invalid memory\nlocation (the list head). Accessing pci_seg-\u003eid after the loop causes\nundefined behavior.\n\nFix this by handling the successful case inside the loop and returning\n-EINVAL after the loop if no matching segment is found.","modified":"2026-09-19T03:47:30.923812123Z","published":"2026-09-17T16:10:17.389Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92505.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/843e149989665f8309ad2efe6048dc76591e1f94"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8aabe0fba01486b5d893e708b05a8fa7f1b7efbb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/99d42aef089a07cfb1d404a7227ac9dc7628b497"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92505.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92505"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"2e98940f123d9c69d4759078aea9a536244c98d3"},{"fixed":"8aabe0fba01486b5d893e708b05a8fa7f1b7efbb"},{"fixed":"99d42aef089a07cfb1d404a7227ac9dc7628b497"},{"fixed":"843e149989665f8309ad2efe6048dc76591e1f94"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92505.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.17.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92505.json"}}],"schema_version":"1.9.0"}