Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constant
Impact
The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constant by a user-supplied page shift, so a large shift produces undefined behaviour and a garbage index into the bitmap that tracks which IOVAs a passthrough device has written. Garbage indexing into that structure is the wrong kind of wrong for a mapping-tracking data structure - treat it as untrusted input reaching IOVA bookkeeping.
Who can reach it
A process holding /dev/iommu supplies an out-of-range page shift (upstream cites 63) on the dirty-tracking bitmap path. Plain ioctl input validation on the fd a passthrough tenant already holds; no host root, no device required. Conditional on iommufd being in use on the node. Same input surface as CVE-2025-40293, which turns the same overflow into a divide-by-zero.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel, and take it together with the CVE-2025-40293 fix since they harden the same path. Interim: keep /dev/iommu out of containers that do not perform passthrough and validate page-size arguments in the VMM layer.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pagesCVE-2023-53630 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table listCVE-2023-54043 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anCVE-2023-54060 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The IOVA allocator's alignment arithmetic wraps near ULONG_MAX and yields aCVE-2025-38688 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd tears down the page-tracking state behind a dma-buf backed IOAS mappingCVE-2026-74328 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.