Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumping
Impact
The cache-invalidation ioctl calls a driver operation that may not exist, jumping through a NULL function pointer on a guest VMM's invalidation request. The host takes an unhandled fault at address zero inside the very path that is supposed to make a guest's IOMMU invalidations real, so the failure mode is both a node crash and an invalidation that never happened.
Who can reach it
A VMM holding /dev/iommu issuing IOMMU_HWPT_INVALIDATE - the nested-translation path qemu uses to forward a guest's IOTLB invalidations to hardware. No host root. Conditional on running nested translation on an IOMMU driver that never implemented the user-invalidation op; the upstream trace is qemu on arm64.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: do not enable nested translation / vIOMMU for tenant VMs on drivers that lack user cache invalidation, and keep /dev/iommu out of tenant containers.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): A tenant using nested translation can ask iommufd to process a cache-invalidationCVE-2026-64289 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): Iommufd accepted any non-zero virtual event queue depth up to U32_MAX, so aCVE-2026-64291 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A failed copy_to_user while draining the iommufd fault queue restarts the sameCVE-2026-64290 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A user-supplied page shift of 63 overflows the divisor in the iommufdCVE-2025-40293 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The vfio type1 info structure is not zeroed before being filled and copied outCVE-2023-54034 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constantCVE-2025-21724 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.