Database/Kernel, userspace & hypervisor
Linux kernel (drivers/iommu/arm/arm-smmu-v3): On Arm hosts a virtual device is mapped to only the first of its Stream
Impact
On Arm hosts a virtual device is mapped to only the first of its Stream IDs, so a guest's invalidation requests never reach the ATC and IOTLB entries belonging to its other streams. Stale device-side translations survive an unmap and the device keeps DMAing into pages the guest already released - an open DMA window into recycled memory. A device with no streams at all makes the kernel read a zero-size pointer out of bounds.
Who can reach it
A tenant VMM using iommufd vDEVICE on an Arm SMMUv3 host (Grace-class AI nodes) creates a vDEVICE for a passthrough device that presents more than one Stream ID, then relies on guest-driven invalidation. Guest-driven and conditional on Arm SMMUv3 with nested translation; not reachable on x86 hosts.
What to do
Update to a stable kernel carrying commits 3808bab5 / 0acbc621. Interim on Grace/Arm nodes: do not enable nested translation (iommufd vDEVICE) for tenant guests, and restrict passthrough to single-Stream-ID devices until patched.
References
Related entries
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): The SMMUv3 SVA path released the pinned ASID without holding a referenceCVE-2022-49426 · Linux kernel (drivers/iommu/arm/arm-smmu-v3)High
- Linux kernel (drivers/iommu/arm/arm-smmu-v3): A process using SVA that unmaps memory drives a flood of SMMU rangeCVE-2023-52484 · Linux kernel (drivers/iommu/arm/arm-smmu-v3)Medium
- perf sched: integer overflow and strcpy overflow parsing untrusted perf.dataCVE-2026-80671 · Linux perf tool, perf sched register_pid() (perf.data parsing)Critical
- KVM arm64: negative stage-1 walk level mis-sizes VNCR TLB invalidation to zeroCVE-2026-89775 · Linux kernel KVM arm64 nested virtualization (VNCR TLB invalidation size, pgshift_level_to_ttl)Critical
- KVM arm64: missing VA sign extension in range-based TLB invalidation decodingCVE-2026-89914 · Linux kernel KVM arm64 nested virtualization (decode_range_tlbi VA sign extension)Critical
- Linux kernel KVM/arm64: VM-wide VNCR mapping counter lets TLB invalidations be missed under nested virtCVE-2026-89915 · Linux kernel KVM/arm64 (nested virtualization VNCR TLB invalidation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.