Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/arm/arm-smmu-v3): A process using SVA that unmaps memory drives a flood of SMMU range
Impact
A process using SVA that unmaps memory drives a flood of SMMU range invalidations, spinning a CPU in the command queue long enough to trip the soft-lockup watchdog - 26 seconds in the upstream report on a 244-CPU box. One tenant's munmap becomes a multi-second stall of the shared SMMU command queue, which stalls invalidation and DMA setup for every other device and tenant behind that SMMU.
Who can reach it
An unprivileged process using SVA/PASID on an arm64 host with SMMUv3 - the configuration on Grace-based GPU nodes. The trigger is an ordinary large munmap in a process that holds an SVA binding: no host root, no crafted request, no race to win. x86 hosts are unaffected.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: do not enable SVA/PASID for tenant workloads on unpatched arm64 SMMUv3 nodes.
References
Related entries
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): On Arm hosts a virtual device is mapped to only the first of its StreamCVE-2026-74573 · Linux kernel (drivers/iommu/arm/arm-smmu-v3)Critical
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): The SMMUv3 SVA path released the pinned ASID without holding a referenceCVE-2022-49426 · Linux kernel (drivers/iommu/arm/arm-smmu-v3)High
- QEMU e1000: guest-triggered stack overflow in the loopback receive path crashes the host QEMU processCVE-2025-12464 · QEMU e1000 network device (e1000_receive_iov loopback path)Medium
- Linux kernel (drivers/iommu): The ARM long-descriptor unmap path returns a negative errno through an unsigned size_tCVE-2026-23067 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/pci): Tearing down a PF that still has SR-IOV VFs takes pci_rescan_remove_lock recursively andCVE-2026-43147 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/iommu/iommufd): A failed copy_to_user while draining the iommufd fault queue restarts the sameCVE-2026-64290 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.