Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): The pfn batch carries the wrong page-frame number forward when a mapping spans a
Impact
The pfn batch carries the wrong page-frame number forward when a mapping spans a batch boundary, so page-pin accounting is applied to pages the tenant never mapped. Host page metadata gets corrupted - pages pinned and unpinned out from under whoever actually owns them.
Who can reach it
A tenant or VMM holding /dev/iommu doing an ordinary IOMMU_IOAS_MAP over a region large enough to cross a pfn batch boundary. No race required, no host root, no special hardware beyond iommufd being the passthrough path.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: keep /dev/iommu out of tenant containers.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without theCVE-2023-53795 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksCVE-2024-26786 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): An error path releases the iommufd fault object and the iommufd context twiceCVE-2024-56624 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Aborting an iommufd object allocation freed the object immediately while theCVE-2025-39966 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd accepts a user address plus length that wraps past zero, then asks the mmCVE-2023-54239 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.