Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table list
Impact
The same hardware page table gets linked into an address space's page-table list twice, corrupting the list. Iteration over that list is what drives map, unmap and invalidation, so a corrupted list means those operations walk freed or wrong entries - stale IOMMU mappings and host memory corruption, scope-changed per the vendor score.
Who can reach it
A holder of /dev/iommu performing an explicit HWPT attach (attaching a device to a specific hardware page table rather than to an IOAS) - the normal flow a VMM uses for a passthrough device. No host root. The upstream note says the in-tree test suite could not cover this path, so it shipped unexercised.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: keep /dev/iommu out of tenant containers and mediate device attach in the host VMM.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anCVE-2023-54060 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The IOVA allocator's alignment arithmetic wraps near ULONG_MAX and yields aCVE-2025-38688 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd tears down the page-tracking state behind a dma-buf backed IOAS mappingCVE-2026-74328 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch carries the wrong page-frame number forward when a mapping spans aCVE-2023-53236 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without theCVE-2023-53795 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksCVE-2024-26786 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.