Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): On the VT-d PASID detach path, if the PASID being removed is not found the code
Impact
On the VT-d PASID detach path, if the PASID being removed is not found the code warned and then used the NULL result anyway, panicking the host. This is the teardown path that revokes a device's access to a tenant address space, so it runs every time a tenant's SVA context or assigned-device PASID goes away - and a panic there is a whole-node outage for every co-tenant.
Who can reach it
Local, on Intel VT-d scalable mode with PASID in use - SVA-capable accelerators or PASID-based device assignment through iommufd. Reached on PASID detach when the PASID is already absent from the domain. Upstream treats this as a should-not-happen state guarded by WARN_ON_ONCE, so a tenant needs to drive the PASID attach/detach path into an inconsistent state first; no host root is required to exercise attach/detach itself.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel on Intel passthrough nodes. Interim: limit which tenants can create and tear down PASID contexts, and do not expose SVA-capable device nodes into untrusted containers.
References
Related entries
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingCVE-2026-53372 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skipsCVE-2026-64591 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still setCVE-2026-74439 · Linux kernel (drivers/iommu/intel)Critical
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noCVE-2024-35843 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMUCVE-2024-56669 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.