Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): Aborting an iommufd object allocation freed the object immediately while the
Impact
Aborting an iommufd object allocation freed the object immediately while the paired file was still sitting on the fput workqueue, so the deferred release() ran against freed memory. Confirmed slab use-after-free found by syzkaller, reachable by anything holding /dev/iommu - the same fd a passthrough tenant needs.
Who can reach it
Any process with /dev/iommu open drives an object-allocation ioctl (the fault/event queue objects are the reported path) down a failure branch so the core aborts after the file has been created. No host root, no device needed beyond the iommufd character device. Conditional on iommufd being in use and /dev/iommu being visible to the tenant - which it is on any node using the modern VFIO/iommufd passthrough stack.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel on passthrough nodes. Interim: remove /dev/iommu from containers that do not do passthrough, and keep it restricted to the VMM process rather than the tenant workload.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Iommufd accepts a user address plus length that wraps past zero, then asks the mmCVE-2023-54239 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The cache-invalidation ioctl calls a driver operation that may not exist, jumpingCVE-2024-46824 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A tenant using nested translation can ask iommufd to process a cache-invalidationCVE-2026-64289 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): Iommufd accepted any non-zero virtual event queue depth up to U32_MAX, so aCVE-2026-64291 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A failed copy_to_user while draining the iommufd fault queue restarts the sameCVE-2026-64290 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.