Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pages
Impact
An unmap runs off the end of the pinned page list and drops pin counts on pages that were never part of the tenant's mapping. Those pages belong to the host kernel or to another tenant, and unpinning them lets memory that is still in use be freed and reallocated. Scope-changed corruption driven from one tenant's ioctl.
Who can reach it
A holder of /dev/iommu issuing IOMMU_IOAS_UNMAP while an access object (an emulated/mediated user of the same IOAS) is present on the range - the ordinary VMM flow. syzkaller-reachable from userspace ioctls; no host root and no hardware precondition beyond iommufd being in use.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: do not hand /dev/iommu to tenants; run passthrough through the host VMM.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table listCVE-2023-54043 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anCVE-2023-54060 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The IOVA allocator's alignment arithmetic wraps near ULONG_MAX and yields aCVE-2025-38688 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd tears down the page-tracking state behind a dma-buf backed IOAS mappingCVE-2026-74328 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch carries the wrong page-frame number forward when a mapping spans aCVE-2023-53236 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without theCVE-2023-53795 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.