GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel x86/mm/pat: split page tables bypass kernel page table tracking, leaving stale IOTLB entries after free

CVSS 8.2CVE-2026-97525Kernel, userspace & hypervisorcurated

Impact

When the change-page-attribute code splits a large page it allocated the PTE directly instead of going through the kernel page table allocator, so the page was never marked as a kernel page table. Since deferred freeing of kernel page tables landed, freeing such a table also skips the IOTLB invalidation added for kernel address space, so the IOMMU can keep translations pointing at memory that has been freed and reused. That is a device-visible stale mapping, which matters specifically on accelerator nodes: GPUs and DPUs using shared virtual addressing translate through the same IOMMU, so a device can read or write reused kernel memory. Exploitation needs high privilege locally, but the blast radius is the whole host, and the fix is a kernel change with no runtime toggle.

Who can reach it

Local, high-privilege context that drives kernel page-attribute changes on a host with IOMMU/SVA-capable devices attached. Not reachable from an unprivileged tenant process.

What to do

Update to a stable kernel carrying the linked commits and reboot each affected host - drain and reboot per node. There is no supported mitigation; the stale IOTLB window exists whenever split kernel page tables are freed on a host using IOMMU SVA.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.