Impact
In the Linux kernel, the iommupt driver may omit the PAGE_SIZE bit from its pgsize_bitmap. Although technically permissible, the mismatch deviates from the intended design and can cause improper DMA mapping or kernel instability. The description does not detail a direct privilege elevation or other direct impact, but the misconfiguration could lead to erroneous memory access behaviors within the kernel.
Affected Systems
The flaw is present in the Linux kernel across all versions that include the iommupt code, including the 7.1 release candidates (rc1 through rc3) and any other kernel releases that incorporate the same driver path.
Risk and Exploitability
The CVSS score of 8.4 signifies high severity, while the EPSS score of less than 1% indicates a low current potential for exploitation. The vulnerability is not listed in the CISA KEV catalog. No exploit path or attack vector is disclosed in the CVE data; thus, it is unclear how an attacker might leverage this design flaw in practice.
OpenCVE Enrichment
Ubuntu USN