Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): VT-d advertised IOMMU dirty-page tracking on units whose page walk is not coherent
Impact
VT-d advertised IOMMU dirty-page tracking on units whose page walk is not coherent with the CPU. Per the Intel spec, the IOMMU then takes a non-recoverable fault the moment it tries to atomically set an A/D bit, so a tenant enabling dirty tracking on its own passthrough domain wedges the IOMMU unit that serves other devices on that node. The kernel CNA scored this scope-changed, which matches: the damage lands outside the requesting domain. Separately, dirty bits that never land quietly break live-migration correctness for any workload relying on them.
Who can reach it
A tenant (or the migration control plane acting on a tenant's request) allocates an iommufd hardware page table with dirty tracking enabled - IOMMU_HWPT_ALLOC with the dirty-tracking flag - for a device behind a VT-d unit that reports scalable-mode A/D support without snooped page-walk coherency. Reachable from /dev/iommu with no host root. Conditional on Intel VT-d, scalable mode, and hardware that reports ecap_slads without ecap_smpwc.
What to do
No fixed release is listed in this record; apply the linked stable commits or run a current stable/LTS kernel. Interim: do not enable IOMMU dirty tracking (and therefore IOMMU-assisted live migration of passthrough devices) on hosts whose VT-d units lack snooped page-walk coherency; gate the dirty-tracking flag in your VMM/control plane rather than letting tenants request it.
References
Related entries
- Linux kernel (drivers/iommu/intel): A live 512-bit VT-d PASID entry is replaced with a single structure copy, so theCVE-2026-45945 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway andCVE-2026-53281 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d walked the PCI DMA-alias list for devices that are not PCI at all whileCVE-2024-50101 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedCVE-2025-38594 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d publishes the address of a freshly allocated PASID table into the PASIDCVE-2026-45862 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.