Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skips
Impact
SVA bind and unbind are asymmetric on VT-d hardware without PCI/PRI - bind skips enabling I/O page faulting, unbind tries to disable it anyway. The unbind path hits a kernel WARNING every time a tenant closes an SVA-using GPU context, which on any node booted with panic_on_warn is an immediate node kill, and it leaves the device's IOPF enablement state out of step with reality.
Who can reach it
A tenant holding /dev/dri/renderD* on an Intel Xe GPU (the upstream report came from xe_vm_close_and_put) or any SVA-capable accelerator simply closes its GPU VM. Conditional on VT-d with SVA enabled and the device lacking PRI support. Repeatable at will from inside the container, with no host privilege.
What to do
Update to 6.18.39 / 6.20 or later. Interim: do not boot tenant nodes with panic_on_warn, which is what turns this from a log line into an outage, and disable SVA where the workload does not need it.
References
Related entries
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still setCVE-2026-74439 · Linux kernel (drivers/iommu/intel)Critical
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noCVE-2024-35843 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMUCVE-2024-56669 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d switched from set-and-check to clear-and-reset when programming device-tableCVE-2025-38216 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d advertised IOMMU dirty-page tracking on units whose page walk is not coherentCVE-2025-40058 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.