Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identity
Impact
On AMD hosts, switching a device's IOMMU group between a DMA domain and an identity (passthrough) domain left the stale dma-iommu operations installed on the device, so the DMA layer then calls IOMMU helpers against a domain that has none. The node oopses on the next allocation - and the switch in question is precisely the identity/DMA transition an operator performs when preparing or reclaiming a card for passthrough.
Who can reach it
Needs host root: unbind the driver, write to /sys/bus/pci/devices/<bdf>/iommu_group/type, rebind. That is node-provisioning automation, not a tenant surface. Affects AMD-Vi hosts; the equivalent VT-d path was already fixed.
What to do
Update to a stable kernel carrying commits f3f2cf46 / d6177a65 - this is old enough that every supported distro kernel has it, so treat it as a floor check rather than an action. Interim: reboot the node after changing iommu_group/type instead of rebinding drivers in place.
References
Related entries
- Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU pageCVE-2023-53789 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): Unbinding a PASID races the I/O page-fault (PPR) notifications still in flightCVE-2023-53501 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceCVE-2022-50505 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): On AMD hosts the Device Table Entry copied to a DMA-alias device is looked up usingCVE-2026-53053 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): Iommu_completion_wait() returned without waiting whenever another CPU had alreadyCVE-2026-68329 · Linux kernel (drivers/iommu/amd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.