Database/Control plane, storage & DevOps
Linux iommu/vt-d (dev-IOTLB flush in scalable mode): The scalable-mode half of the device-IOTLB invalidation problem —
Impact
The scalable-mode half of the device-IOTLB invalidation problem — ATS invalidation is issued or skipped based on device accessibility, and the earlier fix in this area left a gap. Scalable mode is what modern Intel platforms use for PASID-based device assignment, so this is the current-generation path for handing NIC and accelerator functions to tenants. Same underlying concern: a device retaining stale translations after the host revoked them.
Who can reach it
A tenant with a scalable-mode-assigned, ATS-capable PCIe function.
What to do
Kernel upgrade plus host reboot, rolling across passthrough-capable nodes. Verify after patching that IOMMU is in enforcing (not passthrough/iommu=pt) mode for tenant-assigned devices — a surprising number of performance-tuned GPU hosts run with IOMMU translation effectively disabled, which makes this class of bug moot only because the isolation was never there.
References
Related entries
- Linux iommu/vt-d (dev-IOTLB flush for passed-through PCIe devices): The Intel IOMMU driver skips device-IOTLBCVE-2026-43161 · Linux iommu/vt-d (dev-IOTLB flush for passed-through PCIe devices)Medium
- Linux kernel CephFS client: stale xattr blob size hits a BUG_ON and panics the nodeCVE-2026-52961 · Linux kernel CephFS client (__ceph_build_xattrs_blob)Medium
- Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init(): On failure to set the energy-performance preferenceCVE-2026-53121 · Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init()Medium
- Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): The AMD IOMMU driver looked up device IDs withoutCVE-2026-53283 · Linux iommu/amd - devid bounds check in __rlookup_amd_iommu()Medium
- Linuxfabrik monitoring plugins: sudo-authorized checks read arbitrary root-readable files via --testCVE-2026-73974 · Linuxfabrik Monitoring Plugins / linuxfabrik-lib (lib.lftest.test --test path handling)Medium
- community.general ipa_getkeytab: IPA/LDAP bind password written to logs and exposed in the process listCVE-2026-80158 · Ansible community.general ipa_getkeytab module (bind_pw not declared no_log)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.