Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu): Unbinding shared virtual addressing touches the mm's IOMMU state after the domain-free
Impact
Unbinding shared virtual addressing touches the mm's IOMMU state after the domain-free path has already dropped the last reference to that mm, so the kernel reads a freed mm_struct. Any tenant process using SVA on an accelerator can turn an ordinary exit into a use-after-free on host memory, with host code execution as the realistic ceiling.
Who can reach it
A tenant process that bound SVA to a device - GPU SVM through /dev/dri/renderD*, or an accelerator via /dev/vfio/* or uacce - simply unbinds or exits. The upstream report was hit through the Intel Xe GPU driver's VM close path, so a container holding a DRM render node is enough. Conditional on PASID/SVA being enabled on the platform and device; no host root.
What to do
Update to 6.18.20 or later (or your distro's backport of commits 58abeb7b / f5daaa2c). Interim: disable SVA/PASID on tenant nodes (intel_iommu=sm_off on VT-d, or the equivalent driver switch) where the workload does not require shared virtual addressing.
References
Related entries
- Linux kernel (drivers/iommu): The ARM long-descriptor unmap path returns a negative errno through an unsigned size_tCVE-2026-23067 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): An unaligned DMA mapping with no aligned middle section calls into the mapper with lengthCVE-2026-53164 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): When IOMMU registration fails, the core tore down groups and default domains but leftCVE-2025-37877 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): The reset-completion path re-attaches an IOMMU group's domain without checking that theCVE-2026-53280 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butCVE-2025-21770 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroCVE-2023-52910 · Linux kernel (drivers/iommu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.