Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu): The reset-completion path re-attaches an IOMMU group's domain without checking that the
Impact
The reset-completion path re-attaches an IOMMU group's domain without checking that the group has one, so a group whose default domain never allocated crashes the host on the next device reset. A tenant resetting its own passthrough device takes the node down for everyone on it.
Who can reach it
A tenant holding /dev/vfio/* triggers a device reset (VFIO_DEVICE_RESET or device-fd release), on a device whose IOMMU group has a NULL domain. That NULL state requires a default-domain allocation failure at first probe - memory pressure or a driver error during node bring-up - so it is conditional, but once a node is in that state the crash is one tenant ioctl away.
What to do
Update to a stable kernel carrying commits 17194cd0 / d769711f. Interim: check dmesg for default-domain allocation failures during boot and refuse to schedule tenants onto a node that logged one.
References
Related entries
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butCVE-2025-21770 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroCVE-2023-52910 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): A dropped return statement made the IOMMU fault handler process a partial PRICVE-2024-44994 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): This is the substantive fix for stale IOMMU translations of the kernel address spaceCVE-2025-71202 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): The IOMMU group's domain pointer is left stale when a device reset races a detach, andCVE-2026-52952 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu): Every peer-to-peer segment in a scatter-gather list inherits the length of the firstCVE-2026-74277 · Linux kernel (drivers/iommu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.