Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/intel): The VT-d scalable-mode context entry is zeroed while its Present bit is still set
Impact
The VT-d scalable-mode context entry is zeroed while its Present bit is still set, and the PASID directory pages are freed before the IOMMU is told to stop using them. The hardware can keep walking a live-looking entry into memory the kernel has already reallocated, so a tenant's device DMAs into arbitrary reused host memory - a direct tenant-to-host DMA escape, not just a crash.
Who can reach it
Reached on the normal teardown path whenever a passthrough device with a scalable-mode PASID table is released - a tenant closing its /dev/vfio/* device fd, or a VM exiting, is enough to run device_pasid_table_teardown(). Requires VT-d scalable mode (the default on modern Intel platforms with PASID/SVA); no host root.
What to do
Update to a stable kernel carrying commits e9e83bcf / 58871810. The CNA's fixed-version data for this record is not usable as a version target, so verify the commits are in your distro kernel. Interim: disable VT-d scalable mode / PASID (intel_iommu=sm_off) on nodes that hand devices to tenants, accepting the loss of SVA.
References
Related entries
- Linux kernel (drivers/iommu/intel): The VT-d I/O page-fault reporting path looks up the faulting device with noCVE-2024-35843 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): Use-after-free of VT-d cache-tag objects. Device-TLB cache tags outlive the IOMMUCVE-2024-56669 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d switched from set-and-check to clear-and-reset when programming device-tableCVE-2025-38216 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): VT-d advertised IOMMU dirty-page tracking on units whose page walk is not coherentCVE-2025-40058 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): A live 512-bit VT-d PASID entry is replaced with a single structure copy, so theCVE-2026-45945 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (drivers/iommu/intel): When the PASID is not found on the device list, VT-d runs the teardown anyway andCVE-2026-53281 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.