Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/iommufd): Iommufd tears down the page-tracking state behind a dma-buf backed IOAS mapping
Impact
Iommufd tears down the page-tracking state behind a dma-buf backed IOAS mapping while the exporter can still fire invalidation callbacks into it. A tenant can race that teardown into a use-after-free on the structure that decides which host pages its device is allowed to touch, which is a step toward host memory disclosure or a host kernel crash that takes the whole node down.
Who can reach it
A tenant container holding /dev/iommu together with a device fd under /dev/vfio/* sets up an IOAS mapping over a dma-buf (the vfio-pci BAR dma-buf export is the usual source), then races close/detach against the exporter's invalidation callback. No host root and no fabric access are needed - only the passthrough device nodes inside the container, on a kernel new enough to have iommufd dma-buf support.
What to do
Boot a stable kernel carrying the fix commits (0507fced / f2d70dbd); the kernel CNA published no fixed-version list for this one, so track the commits into your distro kernel. Interim: do not expose /dev/iommu directly to tenant containers - keep passthrough behind a VMM the operator controls - and do not enable the vfio-pci dma-buf export path for tenant-held devices.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): The pfn batch carries the wrong page-frame number forward when a mapping spans aCVE-2023-53236 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The destroy ioctl takes a temporary reference on an iommufd object without theCVE-2023-53795 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksCVE-2024-26786 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): An error path releases the iommufd fault object and the iommufd context twiceCVE-2024-56624 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): Aborting an iommufd object allocation freed the object immediately while theCVE-2025-39966 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): A tenant supplies an IOVA and user pointer whose alignment math overflows, soCVE-2024-47719 · Linux kernel (drivers/iommu/iommufd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.