Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU page
Impact
The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU page fault for a device group whose domain was never set up, oopsing the host from inside the fault handler. The faults themselves are generated by devices doing DMA to addresses they are not permitted to touch - exactly what a misbehaving or tenant-programmed device produces.
Who can reach it
An IOMMU page fault raised by a device whose group has no domain configured. A tenant holding a passthrough device can generate IOMMU faults freely by programming bad DMA addresses, but the 'no domain configured' precondition is host-side, so this is not a clean tenant-only path. AMD-Vi (EPYC) hosts; the upstream trace involves an amdgpu device.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: verify every passthrough group has a domain attached before exposing the device to a tenant.
References
Related entries
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): Unbinding a PASID races the I/O page-fault (PPR) notifications still in flightCVE-2023-53501 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceCVE-2022-50505 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): On AMD hosts the Device Table Entry copied to a DMA-alias device is looked up usingCVE-2026-53053 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): Iommu_completion_wait() returned without waiting whenever another CPU had alreadyCVE-2026-68329 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock withCVE-2026-43253 · Linux kernel (drivers/iommu/amd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.