Database/Kernel, userspace & hypervisor
Linux kernel x86/mm/pat: split page tables bypass kernel page table tracking, leaving stale IOTLB entries after free
Impact
When the change-page-attribute code splits a large page it allocated the PTE directly instead of going through the kernel page table allocator, so the page was never marked as a kernel page table. Since deferred freeing of kernel page tables landed, freeing such a table also skips the IOTLB invalidation added for kernel address space, so the IOMMU can keep translations pointing at memory that has been freed and reused. That is a device-visible stale mapping, which matters specifically on accelerator nodes: GPUs and DPUs using shared virtual addressing translate through the same IOMMU, so a device can read or write reused kernel memory. Exploitation needs high privilege locally, but the blast radius is the whole host, and the fix is a kernel change with no runtime toggle.
Who can reach it
Local, high-privilege context that drives kernel page-attribute changes on a host with IOMMU/SVA-capable devices attached. Not reachable from an unprivileged tenant process.
What to do
Update to a stable kernel carrying the linked commits and reboot each affected host - drain and reboot per node. There is no supported mitigation; the stale IOTLB window exists whenever split kernel page tables are freed on a host using IOMMU SVA.
References
Related entries
- Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context whileCVE-2021-47131 · Linux kernel (net/tls)High
- VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write): A malicious actor inside a VMCVE-2024-22273 · VMware ESXi / Workstation / Fusion (storage controller out-of-bounds read/write)High
- Linux kernel (net/xfrm): The error path of xfrm_input leaves the secpath entry pointing at poisoned memory, and theCVE-2024-43878 · Linux kernel (net/xfrm)High
- Linux kernel NVMe target authentication (nvmet-auth DH group setup): CtrlCVE-2024-50215 · Linux kernel NVMe target authentication (nvmet-auth DH group setup)High
- OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc LinuxCVE-2024-6387 · OpenSSH (sshd)High
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.