CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68325

criticalCVSS 9.8covered by 2 sourcesfirst seen 2026-08-10
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET parsers, it does not reject a fifth entry before incrementing the map size. Check the capacity at the common found label before parsing the HID and UID or writing the entry.

CSIRTS triage

What
The AMD IOMMU driver's early ACPI HID map is unbounded, enabling privilege escalation.
Who is affected
Systems with AMD IOMMU using early device initialization.
Urgency
Critical severity (CVSS 9.8) and not yet exploited; patch immediately.
Action
Update to a patched Linux kernel version that addresses CVE-2026-68325.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-68325

Get an email if CVE-2026-68325 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-68325

CVE.org record

Embed the live status

CVE-2026-68325 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68325 status](https://www.csirts.com/badge/CVE-2026-68325)](https://www.csirts.com/cve/CVE-2026-68325)