Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI device
Impact
The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI device and never dropped the reference it took, so every page-request event a device generates permanently pins one more reference to that device. The device can then never be cleanly released back to the pool, and the refcount is driven by a tenant's own workload - reclaiming a GPU or accelerator after a tenant is done with it stops working.
Who can reach it
Device-driven: a tenant running an SVA/PRI workload on an AMD-Vi host makes the assigned device emit page requests, and each one leaks a pci_dev reference in host kernel context. No host privilege needed - the tenant just uses demand paging on its own assigned device. Conditional on AMD-Vi with the amd_iommu_v2 / PPR path active and a PRI-capable device assigned to the tenant.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel on AMD nodes. Interim: disable PRI/ATS on tenant-assigned devices where demand paging is not required, and watch for devices that refuse to unbind after a tenant releases them.
References
Related entries
- Linux kernel (drivers/iommu/amd): On AMD hosts the Device Table Entry copied to a DMA-alias device is looked up usingCVE-2026-53053 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): Iommu_completion_wait() returned without waiting whenever another CPU had alreadyCVE-2026-68329 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock withCVE-2026-43253 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityCVE-2021-47140 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU pageCVE-2023-53789 · Linux kernel (drivers/iommu/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.