Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/riscv): The RISC-V IOMMU driver updated device-directory and process-directory entries
Impact
The RISC-V IOMMU driver updated device-directory and process-directory entries without issuing the invalidations the specification requires, so the hardware keeps using cached device and PASID context after the kernel has moved or freed it. A device therefore keeps translating through a context the kernel believes is gone - a stale mapping that survives detach, which is a DMA window into whatever that memory becomes.
Who can reach it
Reached on any domain attach/detach or PASID setup for a device behind a RISC-V IOMMU - a tenant closing or rebinding a passthrough device is enough. Hardware-conditional: this affects RISC-V platforms only and is not reachable on the x86 or Arm nodes that make up essentially all GPU fleets today. Track it only if RISC-V hosts are in the estate.
What to do
Update to a stable kernel carrying commits 3f917d9b / d99d1c13 on RISC-V hosts. No action needed on x86 (VT-d/AMD-Vi) or Arm SMMU nodes.
References
Related entries
- Linux kernel (net/xfrm): An unlocked read of the IPTFS reassembly state lets two CPUs disagree about who owns a socketCVE-2026-53240 · Linux kernel (net/xfrm)High
- Linux KVM arm64: page-table walks without kvm->srcu can race memslot changesCVE-2026-53277 · Linux kernel KVM arm64 (__kvm_at_s12 / __kvm_find_s1_desc_level page-table walks)High
- Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway andCVE-2026-53281 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/vfio/pci): When a tenant closes its passed-through PCI device, vfio disables the function beforeCVE-2026-53322 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (arch/x86/kvm/mmu): Shadow-page lookup reuses a page without comparing its role, so a direct (2MB) shadowCVE-2026-53359 · Linux kernel (arch/x86/kvm/mmu)High
- Linux KVM - GHCB v2+ scratch area location enforcement: KVM did not require the GHCB software scratch area to liveCVE-2026-53360 · Linux KVM - GHCB v2+ scratch area location enforcementHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.