Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d device
Impact
A device that does not support ATS never gets inserted into the VT-d device red-black tree, but a later probe failure still runs the removal, which treats the zeroed node as a tree root and corrupts the tree. That tree is what maps an incoming device request back to its device context, so corrupting it means faults and ATS lookups can resolve to the wrong device - and the corruption itself is an out-of-bounds write into kernel memory.
Who can reach it
Requires a probe failure on a device behind VT-d, so the trigger is host-side: driver binding during boot or during passthrough provisioning, on a device without ATS support where a later probe step fails. Not tenant-driven, but the damaged structure is shared by every device on the IOMMU, so the fallout lands on tenant devices.
What to do
Update to a stable kernel carrying commits f5102e0f / d16923a4. Interim: watch for probe failures in the VT-d path during node bring-up and refuse to schedule tenants onto a node that logged one until it is rebooted.
References
Related entries
- Linux kernel (drivers/iommu/intel): VT-d walked the PCI DMA-alias list for devices that are not PCI at all whileCVE-2024-50101 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedCVE-2025-38594 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d publishes the address of a freshly allocated PASID table into the PASIDCVE-2026-45862 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 512-bit VT-d PASID entry is zeroed all at once while still marked present, andCVE-2026-45894 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): The 128-bit VT-d context entry is zeroed with multiple writes while its Present bitCVE-2026-45944 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): Killing a VM that has a device attached through the VT-d nested/PASID path makesCVE-2026-52953 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.