Back

MEDIUM

iommufd: Don't overflow during division for dirty tracking

Published Dec 8, 2025

Description

If pgshift is 63 then BITS_PER_TYPE(*bitmap->bitmap) * pgsize will overflow to 0 and this triggers divide by 0.

In this case the index should just be 0, so reorganize things to divide by shift and avoid hitting any overflows.

Affected products

Remediation

Red Hat statement

iommufd is used for userspace IOMMU management, primarily in virtualization contexts. Triggering requires specific pgshift values of 63, which is an edge case unlikely in normal operation.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 8, 2025
Updated May 11, 2026
Reserved Apr 16, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 8, 2025