Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): Killing a VM that has a device attached through the VT-d nested/PASID path makes
Impact
Killing a VM that has a device attached through the VT-d nested/PASID path makes the host dereference past the end of a static blocked-domain object and take a general protection fault. A tenant kills its own qemu and the host kernel goes down, taking every other tenant sharing that node with it.
Who can reach it
A tenant VM (or its VMM) with a device bound through vfio + iommufd nested domains and a PASID attached simply exits or is killed - releasing the vfio device fd runs the reset path that hits the bug. Conditional on VT-d scalable mode with nested translation in use; no host root and no fabric access needed.
What to do
Update to a stable kernel carrying commits 88397fad / 1e659db4. Interim: avoid VT-d nested translation (vIOMMU) for tenant VMs on unpatched hosts, and drain co-tenants off nodes that run nested-PASID passthrough until the kernel is updated.
References
Related entries
- Linux kernel (drivers/iommu/intel): The whole node hangs. VT-d keeps re-issuing an ATS device-TLB invalidation to aCVE-2024-26891 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): Attaching a nested parent domain skips allocating the invalidation batch structureCVE-2024-56668 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On device release VT-d could dereference a NULL domain and, separately, leave theCVE-2024-27079 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On the VT-d PASID detach path, if the PASID being removed is not found the codeCVE-2025-21833 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty trackingCVE-2026-53372 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skipsCVE-2026-64591 · Linux kernel (drivers/iommu/intel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.