Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/amd): On AMD hosts the Device Table Entry copied to a DMA-alias device is looked up using
Impact
On AMD hosts the Device Table Entry copied to a DMA-alias device is looked up using the wrong source device ID, so an alias can be programmed with another device's - or a stale - translation table. The aliased function then DMAs through an IOMMU domain that does not belong to it, which is exactly the cross-tenant DMA the IOMMU is there to prevent.
Who can reach it
No tenant action is required - the wrong Device Table Entry is installed when the device is set up. It bites on any AMD-Vi host where a passed-through function has a PCI DMA alias: devices behind PCIe-to-PCI bridges and multi-function endpoints covered by alias quirks, which includes a lot of real GPU and NIC topologies. From then on the tenant's device translates through the wrong domain.
What to do
Update to a stable kernel carrying commits dbd76a53 / 20b3c566 (the CNA's fixed-version field on this record is not a usable target - confirm the commits in your distro kernel). Interim: audit which passthrough devices have DMA aliases (check the IOMMU group membership against the PCI topology) and avoid handing out aliased functions to tenants until patched.
References
Related entries
- Linux kernel (drivers/iommu/amd): Iommu_completion_wait() returned without waiting whenever another CPU had alreadyCVE-2026-68329 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock withCVE-2026-43253 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityCVE-2021-47140 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU pageCVE-2023-53789 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.