Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave the
Impact
On device release VT-d could dereference a NULL domain and, separately, leave the device's scalable-mode context entry uncleared. A context entry that survives device release is a translation the hardware still honours for whatever occupies that bus/device/function next - the stale-mapping shape of a DMA isolation break - and the NULL dereference itself oopses the host.
Who can reach it
Reached on device release/detach: a device leaving its IOMMU group, which on a GPU node happens on driver unbind, VF teardown, or when a tenant's passthrough function is returned to the host. The upstream reproducer is the kdump kernel, where deferred attach means the domain pointer is not yet assigned. Needs host-side device lifecycle events rather than a tenant ioctl - but the residue it leaves is exactly what the next tenant on that BDF would inherit.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim controls: avoid rapid rebind/reassign cycles of passthrough functions between tenants, and force a full device reset and re-probe before handing a function to a new tenant.
References
Related entries
- Linux kernel (drivers/iommu/intel): On the VT-d PASID detach path, if the PASID being removed is not found the codeCVE-2025-21833 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingCVE-2026-53372 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skipsCVE-2026-64591 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still setCVE-2026-74439 · Linux kernel (drivers/iommu/intel)Critical
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noCVE-2024-35843 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.