Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): A tenant using nested translation can ask iommufd to process a cache-invalidation
Impact
A tenant using nested translation can ask iommufd to process a cache-invalidation batch of essentially unbounded size, pinning a CPU in a non-preemptible loop until the soft-lockup watchdog fires. On a node booted with softlockup_panic that is a panic; otherwise it is a burnt core plus a wedged IOMMU invalidation path that every other tenant on the box shares.
Who can reach it
One IOMMUFD_CMD_HWPT_INVALIDATE ioctl from a tenant container holding /dev/iommu, with entry_num or entry_len set near U32_MAX. No host root and no special hardware beyond a nested/vIOMMU setup (VT-d nested is the case called out in the fix). Trivially repeatable, so a tenant can burn cores one at a time.
What to do
Update to a stable kernel carrying commits d2bd041e / 32ca4aed. Interim: do not expose /dev/iommu to untrusted tenants directly - run passthrough through an operator-controlled VMM - and do not boot tenant nodes with softlockup_panic, which converts this from a stalled core into a full node panic.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): Iommufd accepted any non-zero virtual event queue depth up to U32_MAX, so aCVE-2026-64291 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A failed copy_to_user while draining the iommufd fault queue restarts the sameCVE-2026-64290 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): A user-supplied page shift of 63 overflows the divisor in the iommufdCVE-2025-40293 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The vfio type1 info structure is not zeroed before being filled and copied outCVE-2023-54034 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constantCVE-2025-21724 · Linux kernel (drivers/iommu/iommufd)Medium
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.