Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/arm/arm-smmu-v3): The SMMUv3 SVA path released the pinned ASID without holding a reference
Impact
The SMMUv3 SVA path released the pinned ASID without holding a reference on the mm, so the mm can be freed while the IOMMU still believes it owns that address-space ID. That is a use-after-free on the structure that decides which process's page tables a device is allowed to walk - the classic route from a local unprivileged process to kernel memory corruption, and on Arm hosts to an accelerator pointed at recycled page tables.
Who can reach it
Local, on Arm64 hosts using SMMUv3 SVA (this is the IOMMU on Grace/Grace-Hopper class systems). Any process that can bind an SVA/PASID context through an accelerator character device - a compute accelerator, an SVA-capable NIC queue, or an in-kernel SVA consumer - and then exit while the ASID is still pinned reaches it. No host root required; requires CONFIG_ARM_SMMU_V3_SVA and a device driver that offers SVA binding to userspace.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel on Arm nodes. Interim: disable SVA for accelerator drivers that expose it to tenants, or do not expose SVA-capable device nodes into tenant containers.
References
Related entries
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): A process using SVA that unmaps memory drives a flood of SMMU rangeCVE-2023-52484 · Linux kernel (drivers/iommu/arm/arm-smmu-v3)Medium
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): On Arm hosts a virtual device is mapped to only the first of its StreamCVE-2026-74573 · Linux kernel (drivers/iommu/arm/arm-smmu-v3)Critical
- Linux kernel (arch/x86/kvm/mmu): When guest memory is backed by a VM_PFNMAP mapping, KVM derived the target page frameCVE-2022-49562 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (drivers/gpu/drm/i915/gt): The GPU migration copy path used plain ints for sizes that a tenant controlsCVE-2022-49963 · Linux kernel (drivers/gpu/drm/i915/gt)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A double free in the amdkfd (KFD compute driverCVE-2022-50303 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2022-50354 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.