Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu): This is the substantive fix for stale IOMMU translations of the kernel address space
Impact
This is the substantive fix for stale IOMMU translations of the kernel address space under SVA. Without it the IOMMU keeps cached paging-cache entries for kernel page-table pages that have already been freed and handed out for other use, so a device can DMA through a translation that now points at attacker-placed data - arbitrary physical memory access and privilege escalation from a device a tenant drives. The kernel CNA scored it scope-changed, which is the right read: the blast radius is the host, not the tenant.
Who can reach it
Local unprivileged, on x86 hosts with IOMMU SVA and an SVA/PASID-capable device the tenant can bind (Intel DSA/IAA, SVM-capable GPUs, PRI-capable NICs). The attacker recycles kernel page-table pages through ordinary means - the series calls out vfree() as the common, unprivileged trigger - while an SVA-bound device still has the stale entry cached, then grooms the reallocated page. Requires CONFIG_IOMMU_SVA and a driver exposing SVA binding to userspace.
What to do
No fixed release is listed in this record; take the whole series from the linked stable commits (this plus CVE-2025-71089) or run a current stable/LTS kernel that carries it. Interim: disable SVA/PASID on tenant-facing devices and keep SVA-capable accelerator nodes out of untrusted containers - the upstream series itself disables x86 SVA outright until this invalidation path exists.
References
Related entries
- Linux kernel (drivers/iommu): The IOMMU group's domain pointer is left stale when a device reset races a detach, andCVE-2026-52952 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): Every peer-to-peer segment in a scatter-gather list inherits the length of the firstCVE-2026-74277 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): An I/O page-fault group is handed to userspace through iommufd while still sitting on theCVE-2026-74520 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): With iommufd, a tenant can change a passthrough device's IOMMU domain while MSICVE-2025-38062 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): In an SVA context the IOMMU walks and caches the CPU's page tables, and on x86 everyCVE-2025-71089 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): Unbinding shared virtual addressing touches the mm's IOMMU state after the domain-freeCVE-2026-23429 · Linux kernel (drivers/iommu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.