Reliance on undefined behavior in Linux kernel - CVE-2026-92505
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger undefined behavior.
The vulnerability exists due to reliance on undefined behavior in the AMD IOMMU devid_write debugfs function when processing a device ID for which no matching PCI segment is found. A local user can write such a device ID to the debugfs interface to trigger undefined behavior.