CVE-2026-68324

Source
https://cve.org/CVERecord?id=CVE-2026-68324
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68324.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68324
Downstream
Published
2026-08-10T12:03:00Z
Modified
2026-08-21T03:30:37Z
Summary
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
Details

In the Linux kernel, the following vulnerability has been resolved:

iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()

dmar_latency_disable() intends to zero out only the single latency_statistic entry for the given type, but the memset size was computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire array starting from &lstat[type].

When type > 0, this writes beyond the end of the allocated array, corrupting adjacent memory.

Fix by using sizeof(*lstat) to clear only the target entry.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68324.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
55ee5e67a59a1b6f388d7a1c7b24022145f47a3e
Fixed
80f3605991461679c298ea2045c350ee3cf36de3
Fixed
104d89cf5b01cb66ff975d91ed42f61b3904df53
Fixed
3078d82e7fe9048a2b90a992e71af7cd7ef881fa
Fixed
866a35735e56b9dc81cbc33899255134adf6d8b3
Fixed
d06fea9b85f038690f55e72fe0c45e113715a85a
Fixed
0e28ca1c3204b51068579defc904a0dfba5e5c57
Fixed
754f8efe45f87e3a9c6871b645b2f9d46d1b407b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68324.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.14.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68324.json"