CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of virtual devices (vDEVICEs) in the arm-smmu-v3 IOMMU, specifically when devices with multiple streams are incorrectly mapped, leading to potential out-of-bounds reads. This flaw can compromise the integrity of guest virtual address spaces by allowing invalidation operations to fail silently, which may expose sensitive data or lead to system instability. Organizations using Linux on ARM architectures, particularly those leveraging virtualization, should prioritize addressing this issue to mitigate potential security risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE arm_vsmmu_vsid_to_sid() maps a guest's vSID to a single physical Stream ID taken from master->streams[0], assuming a device has exactly one stream. A device with several streams gets only its first one mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB entries; a device with none makes master->streams a ZERO_SIZE_PTR, read out of bounds. Add an arm_vsmmu_vdevice_init() op to reject the vDEVICE with -EOPNOTSUPP when master->num_streams is not one, rather than mapping it silently.