Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu): The ARM long-descriptor unmap path returns a negative errno through an unsigned size_t
Impact
The ARM long-descriptor unmap path returns a negative errno through an unsigned size_t, so the caller is told roughly 2^64 bytes were unmapped. That value is added to the IOVA in the unmap loop, overflowing the address and hitting a BUG_ON - a kernel panic that takes every tenant on the node with it - while the unmap itself walks into addresses that were never part of the request.
Who can reach it
Reached when an unmap request covers a page-table entry that is already absent. On a passthrough node the unmap originates from a tenant's VMM through vfio or iommufd, though the upper layers normally track mapped areas well enough that hitting an absent entry means state is already inconsistent (a WARN fires first). arm64 hosts using io-pgtable-arm, i.e. SMMUv3 on Grace-class GPU nodes. x86 is unaffected.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. No practical interim control on affected arm64 nodes beyond patching.
References
Related entries
- Linux kernel (drivers/iommu): An unaligned DMA mapping with no aligned middle section calls into the mapper with lengthCVE-2026-53164 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): When IOMMU registration fails, the core tore down groups and default domains but leftCVE-2025-37877 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): The reset-completion path re-attaches an IOMMU group's domain without checking that theCVE-2026-53280 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butCVE-2025-21770 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroCVE-2023-52910 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): A dropped return statement made the IOMMU fault handler process a partial PRICVE-2024-44994 · Linux kernel (drivers/iommu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.