Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without the
Impact
The destroy ioctl takes a temporary reference on an iommufd object without the lock that every other temporary reference is required to hold. Two racing destroys can therefore drop the last reference on an object still in use, breaking the lifetime rule for the fd that owns a tenant's entire IOMMU address space and page tables.
Who can reach it
A holder of /dev/iommu racing two IOMMUFD_DESTROY ioctls against each other, or a destroy against close(). syzkaller-reachable from plain userspace ioctls; no host root, no hardware precondition beyond iommufd being the passthrough path.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: keep /dev/iommu out of tenant containers.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksCVE-2024-26786 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): An error path releases the iommufd fault object and the iommufd context twiceCVE-2024-56624 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Aborting an iommufd object allocation freed the object immediately while theCVE-2025-39966 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd accepts a user address plus length that wraps past zero, then asks the mmCVE-2023-54239 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumpingCVE-2024-46824 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.