Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stopped
Impact
VT-d tore the device off the I/O page-fault queue before the hardware had stopped generating faults and before in-flight ones were drained, so the fault worker kept running against freed fault groups. Result is a refcount underflow and use-after-free in kernel context - reachable by a tenant that simply closes an SVA context while its device still has page requests outstanding.
Who can reach it
Local, on Intel hosts with VT-d scalable mode and an SVA/PASID-capable device exposed to tenants (DSA/IAA accelerators, SVM-capable GPUs, PRI-capable NICs). The tenant binds SVA, drives the device to generate page requests against unmapped addresses, then unbinds or exits so the last IOPF-capable domain detaches while faults are still queued. No host root required; needs PRI/IOPF enabled on the device.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel. Interim: disable PRI/SVA on devices handed to tenants, or stop exposing SVA-capable accelerator device nodes into tenant containers.
References
Related entries
- Linux kernel (drivers/iommu/intel): VT-d publishes the address of a freshly allocated PASID table into the PASIDCVE-2026-45862 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 512-bit VT-d PASID entry is zeroed all at once while still marked present, andCVE-2026-45894 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 128-bit VT-d context entry is zeroed with multiple writes while its Present bitCVE-2026-45944 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): Killing a VM that has a device attached through the VT-d nested/PASID path makesCVE-2026-52953 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The whole node hangs. VT-d keeps re-issuing an ATS device-TLB invalidation to aCVE-2024-26891 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structureCVE-2024-56668 · Linux kernel (drivers/iommu/intel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.