Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/amd): Iommu_completion_wait() returned without waiting whenever another CPU had already
Impact
Iommu_completion_wait() returned without waiting whenever another CPU had already queued a completion-wait, so a CPU could free page-table pages while the AMD IOMMU was still walking the translations those pages describe. The tenant's device then DMAs through a page table backed by memory the host has reallocated - a stale mapping that is a direct tenant-to-host DMA read/write escape, and the most serious bug in this batch.
Who can reach it
Any high-rate DMA map/unmap workload on an AMD-Vi host reaches it: a tenant hammering unmap through a passed-through NIC or GPU, or issuing VFIO_IOMMU_UNMAP_DMA in a loop from /dev/vfio/*, while a second CPU does concurrent IOMMU work. No host root, no fabric access; the race gets easier the busier the node is, so a co-tenant generating IOMMU traffic helps the attacker.
What to do
Update to a stable kernel carrying commits ab7faf5a / 93494bd4 on every AMD-Vi node. Interim controls are weak: reducing unmap rate or pinning tenants to fewer sockets only narrows the window. Treat this as a mandatory reboot on AMD hosts that run passthrough for tenants.
References
Related entries
- Linux kernel (drivers/iommu/amd): The AMD IOMMU busy-waits for command completion while holding its spinlock withCVE-2026-43253 · Linux kernel (drivers/iommu/amd)High
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): On AMD hosts, switching a device's IOMMU group between a DMA domain and an identityCVE-2021-47140 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi interrupt thread dereferences a NULL domain while reporting an IOMMU pageCVE-2023-53789 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi updated the domain's I/O page-table mode before running the code that freesCVE-2022-48904 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (drivers/iommu/amd): Unbinding a PASID races the I/O page-fault (PPR) notifications still in flightCVE-2023-53501 · Linux kernel (drivers/iommu/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.