Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMU
Impact
Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMU domain they belong to, so a later IOTLB flush walks freed kernel memory. The upstream report reproduces it exactly as an operator would hit it - several VFs from different PFs passed through to one userspace process - and the crash arrives via the tenant's own DMA unmap ioctl. Scope-changed: a tenant's ordinary unmap corrupts host kernel state.
Who can reach it
A tenant process or VM holding /dev/vfio/* with one or more ATS-capable VFs assigned. The freed cache tag is reached from vfio_iommu_type1's VFIO_IOMMU_UNMAP_DMA path, i.e. an ioctl the tenant issues itself. Conditional on Intel VT-d with device-TLB/ATS enabled on the assigned functions. No host root required.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim controls: avoid assigning VFs from multiple different PFs to a single tenant, and disable ATS on assigned functions where the device allows it.
References
Related entries
- Linux kernel (drivers/iommu/intel): VT-d switched from set-and-check to clear-and-reset when programming device-tableCVE-2025-38216 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d advertised IOMMU dirty-page tracking on units whose page walk is not coherentCVE-2025-40058 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): A live 512-bit VT-d PASID entry is replaced with a single structure copy, so theCVE-2026-45945 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway andCVE-2026-53281 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d walked the PCI DMA-alias list for devices that are not PCI at all whileCVE-2024-50101 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.