Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): The vfio type1 info structure is not zeroed before being filled and copied out
Impact
The vfio type1 info structure is not zeroed before being filled and copied out, and the copy-in covers fewer bytes than the struct, so padding bytes of kernel stack are handed to the caller. Kernel memory disclosure to a tenant through iommufd's vfio compatibility ioctl.
Who can reach it
A tenant or VMM holding /dev/iommu, or a vfio container backed by iommufd, calling the type1 GET_INFO ioctl through the compat layer. One ioctl, no race, no host root.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: keep /dev/iommu out of tenant containers.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constantCVE-2025-21724 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pagesCVE-2023-53630 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table listCVE-2023-54043 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anCVE-2023-54060 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The IOVA allocator's alignment arithmetic wraps near ULONG_MAX and yields aCVE-2025-38688 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.