Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): A live 512-bit VT-d PASID entry is replaced with a single structure copy, so the
Impact
A live 512-bit VT-d PASID entry is replaced with a single structure copy, so the IOMMU can fetch a half-old, half-new entry and briefly translate through a page table that belongs to neither the old nor the new domain. Domain replacement is exactly what happens when a passthrough device is moved between address spaces or between tenants, which is where a torn entry turns into DMA against the wrong tenant's memory.
Who can reach it
Triggered on the domain-replacement path, which a tenant or its VMM drives through iommufd (attach/replace a HWPT) or through vfio device rebinding while the device is actively issuing DMA. Conditional on VT-d scalable mode with PASID; no host root. Timing-dependent, but the attacker controls both the replacement and the DMA traffic that races it.
What to do
Update to a stable kernel carrying commits 47180078 / 66a7aff4. Interim: quiesce the device (stop tenant DMA) around any domain attach/replace, and avoid runtime HWPT replacement for tenant devices on unpatched hosts.
References
Related entries
- Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway andCVE-2026-53281 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d walked the PCI DMA-alias list for devices that are not PCI at all whileCVE-2024-50101 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedCVE-2025-38594 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d publishes the address of a freshly allocated PASID table into the PASIDCVE-2026-45862 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 512-bit VT-d PASID entry is zeroed all at once while still marked present, andCVE-2026-45894 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.