Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): The 128-bit VT-d context entry is zeroed with multiple writes while its Present bit
Impact
The 128-bit VT-d context entry is zeroed with multiple writes while its Present bit is still set, so the IOMMU can fetch a torn entry - some fields already cleared, still marked present. The hardware then translates a device's DMA through a half-demolished context, which is undefined behaviour on the structure that binds a device to its tenant's address space.
Who can reach it
Runs on the device-context teardown path: unbinding a device from its domain, which happens when a tenant releases a passthrough device or the operator rebinds a card. Requires VT-d and a race between the CPU zeroing the entry and a hardware fetch, so it is timing-dependent - but the timing is driven by the tenant's own DMA traffic during teardown.
What to do
Update to a stable kernel carrying commits c716a59e / d2138abc. Interim: quiesce device DMA before releasing a passthrough device (stop the tenant workload, then unbind) rather than tearing down under active traffic.
References
Related entries
- Linux kernel (drivers/iommu/intel): Killing a VM that has a device attached through the VT-d nested/PASID path makesCVE-2026-52953 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The whole node hangs. VT-d keeps re-issuing an ATS device-TLB invalidation to aCVE-2024-26891 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structureCVE-2024-56668 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave theCVE-2024-27079 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On the VT-d PASID detach path, if the PASID being removed is not found the codeCVE-2025-21833 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingCVE-2026-53372 · Linux kernel (drivers/iommu/intel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.