Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu): The IOMMU group's domain pointer is left stale when a device reset races a detach, and
Impact
The IOMMU group's domain pointer is left stale when a device reset races a detach, and the reset-completion path then re-attaches a domain that has already been freed. That is a use-after-free on the object that defines which host memory a passed-through device may DMA to - the strongest primitive a tenant device can get for reaching outside its own address space.
Who can reach it
A tenant holding /dev/vfio/* triggers a device reset - VFIO_DEVICE_RESET, or simply closing the device fd, which resets on release - while another thread detaches or replaces the domain. Multi-device IOMMU groups and PCI DMA-alias quirks widen the window, and those are common in GPU topologies behind PCIe switches. No host root required.
What to do
Update to a stable kernel carrying commits 8fc289e8 / 5474e6e1. Interim: put each tenant's passthrough devices in a single-device IOMMU group where the topology allows it (ACS on the upstream switch ports), and avoid handing tenants devices whose group contains functions belonging to other workloads.
References
Related entries
- Linux kernel (drivers/iommu): Every peer-to-peer segment in a scatter-gather list inherits the length of the firstCVE-2026-74277 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): An I/O page-fault group is handed to userspace through iommufd while still sitting on theCVE-2026-74520 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): With iommufd, a tenant can change a passthrough device's IOMMU domain while MSICVE-2025-38062 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): In an SVA context the IOMMU walks and caches the CPU's page tables, and on x86 everyCVE-2025-71089 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): Unbinding shared virtual addressing touches the mm's IOMMU state after the domain-freeCVE-2026-23429 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): The ARM long-descriptor unmap path returns a negative errno through an unsigned size_tCVE-2026-23067 · Linux kernel (drivers/iommu)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.