Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): VT-d accepted a PASID attachment to a nested domain whose parent has dirty tracking
Impact
VT-d accepted a PASID attachment to a nested domain whose parent has dirty tracking configured, even though the kernel cannot track dirty pages in that configuration. Dirty pages are then silently dropped, so a tenant VM that is live-migrated or checkpointed comes back with stale memory - guest data corruption the operator produced, with no error anywhere.
Who can reach it
Reached by the VMM / control plane driving iommufd: attach a PASID to a nested domain while the nesting parent has IOMMU dirty tracking enabled. Conditional on VT-d scalable mode with nested translation and dirty-tracking-based live migration in use. Not a tenant-driven memory-safety break - the exposure is to the operator's own migration path.
What to do
Update to a stable kernel carrying commits 3ea9ce75 / 9009c1af, which fails the attach up front instead of losing pages. Interim: do not combine PASID attachment to nested domains with IOMMU dirty tracking - disable dirty-tracking-based live migration for guests using vIOMMU nesting.
References
Related entries
- Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skipsCVE-2026-64591 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still setCVE-2026-74439 · Linux kernel (drivers/iommu/intel)Critical
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noCVE-2024-35843 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMUCVE-2024-56669 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d switched from set-and-check to clear-and-reset when programming device-tableCVE-2025-38216 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.