SB20251226319 - Buffer overflow in Linux kernel iommu amd driver
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2023-54057)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the parse_ivrs_hpet() and parse_ivrs_acpihid() functions in drivers/iommu/amd/init.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2ae19ac3ea82a5b87a81c10adbb497c9e58bdd60
- https://git.kernel.org/stable/c/5e97dc748d13fad582136ba0c8cec215c7aeeb17
- https://git.kernel.org/stable/c/63cd11165e5e0ea2012254c764003eda1f9adb7d
- https://git.kernel.org/stable/c/b6b26d86c61c441144c72f842f7469bb686e1211
- https://git.kernel.org/stable/c/c513043e0afe6a8ba79d00af358655afabb576d2
- https://git.kernel.org/stable/c/f2a5ec7f7b28f9b9cd5fac232ff51019a7f7b9e9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.175