Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): An error path releases the iommufd fault object and the iommufd context twice
Impact
An error path releases the iommufd fault object and the iommufd context twice, driving their refcounts through zero. The object that owns a tenant's entire IOMMU address space gets freed while still referenced, giving a use-after-free on host kernel memory reachable from a tenant ioctl.
Who can reach it
A process holding /dev/iommu - the VMM (qemu) for a passthrough VM, or any container that was given the iommufd node. The tenant calls the fault-queue allocation ioctl and forces the tail of the handler to fail (e.g. by supplying a bad output pointer), which runs the double-release path. Conditional on iommufd being in use rather than the legacy vfio type1 container; iommufd is the default path for nested translation and I/O page-fault handling.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim controls: do not expose /dev/iommu to tenant containers, and keep passthrough on the legacy vfio type1 container where the workload allows it.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): Aborting an iommufd object allocation freed the object immediately while theCVE-2025-39966 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd accepts a user address plus length that wraps past zero, then asks the mmCVE-2023-54239 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumpingCVE-2024-46824 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A tenant using nested translation can ask iommufd to process a cache-invalidationCVE-2026-64289 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): Iommufd accepted any non-zero virtual event queue depth up to U32_MAX, so aCVE-2026-64291 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.