Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway and
Impact
When the PASID is not found on the device list, VT-d runs the teardown anyway and decrements a reference count it never took, so the domain's refcount can reach zero while other devices are still attached to it. The IOMMU domain is then freed under live devices - a use-after-free on the translation state of unrelated passthrough devices that share that domain, plus a NULL dereference on the simpler path.
Who can reach it
A tenant detaching or closing a PASID-attached device through /dev/vfio/* plus /dev/iommu drives the teardown; hitting the not-found case takes a detach that races another detach or a domain replacement. Conditional on VT-d scalable mode with PASID in use. The blast radius is other devices sharing the same domain, which is what makes this cross-tenant rather than self-inflicted.
What to do
Update to a stable kernel carrying commits 9022cb9a / cdfe3c9f (the record's fixed-version list predates the fix and is not a usable target). Interim: avoid sharing one IOMMU domain across devices belonging to different tenants, and disable PASID/scalable mode where SVA is not required.
References
Related entries
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d walked the PCI DMA-alias list for devices that are not PCI at all whileCVE-2024-50101 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedCVE-2025-38594 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d publishes the address of a freshly allocated PASID table into the PASIDCVE-2026-45862 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 512-bit VT-d PASID entry is zeroed all at once while still marked present, andCVE-2026-45894 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 128-bit VT-d context entry is zeroed with multiple writes while its Present bitCVE-2026-45944 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.