Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock with
Impact
The AMD IOMMU busy-waits for command completion while holding its spinlock with interrupts disabled, so under heavy DMA map/unmap pressure the whole node soft-locks. One tenant generating aggressive IOMMU traffic stalls every other tenant's device on that IOMMU - a shared-node availability failure, and the kernel CNA rated it network-reachable because fabric traffic is what drives the mapping churn.
Who can reach it
Any workload that drives high-rate DMA mapping on an AMD-Vi host with iommu.strict=1: a tenant hammering unmap through a passed-through NIC or GPU, or high packet rates through an SR-IOV VF. Conditional on strict (non-deferred) IOMMU invalidation mode; no host privilege.
What to do
Update to a stable kernel carrying commits f2f65b28 / 715c2631. Interim: on AMD hosts, avoid iommu.strict=1 where your threat model tolerates deferred invalidation (note that lazy mode itself widens the stale-mapping window, so this is a genuine trade-off), and rate-limit tenant DMA mapping churn if the stack allows.
References
Related entries
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityCVE-2021-47140 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU pageCVE-2023-53789 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): Unbinding a PASID races the I/O page-fault (PPR) notifications still in flightCVE-2023-53501 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceCVE-2022-50505 · Linux kernel (drivers/iommu/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.