Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structure
Impact
Attaching a nested parent domain skips allocating the invalidation batch structure, so the first DMA map into that domain dereferences NULL inside the cache-flush path and oopses the host. The same allocation is done without a lock, so it can also be raced and leaked. The crash arrives from a guest VMM's ordinary map operation.
Who can reach it
A VMM holding /dev/iommu that has created a nested parent domain (vIOMMU / nested translation for a passthrough device) and then calls IOMMU_IOAS_MAP. The upstream trace is qemu-system-x86 on Intel VT-d. No host root. Conditional on nested translation being enabled - plain single-level passthrough does not take this path.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: do not expose nested translation / vIOMMU to tenant VMs on unpatched VT-d hosts.
References
Related entries
- Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave theCVE-2024-27079 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On the VT-d PASID detach path, if the PASID being removed is not found the codeCVE-2025-21833 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingCVE-2026-53372 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skipsCVE-2026-64591 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still setCVE-2026-74439 · Linux kernel (drivers/iommu/intel)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.