Database/Kernel, userspace & hypervisor
Linux AMD IOMMU: sign-discarding error check lets nested domains use an unallocated domain ID
Impact
amd_iommu_alloc_domain_nested() stores the int return of amd_iommu_pdom_id_alloc() into a u32 before testing it, so a negative errno becomes a large positive value and the failure check never fires. Under ID-space exhaustion or memory pressure the nested IOMMU domain is set up with a host domain ID that was never allocated, instead of failing with -ENOSPC. Nested IOMMU domains are what back device passthrough to guests, so on an AMD GPU virtualization host this means a passthrough domain sharing or colliding with an ID that belongs elsewhere - the isolation boundary that keeps a tenant's passed-through GPU or NIC from DMAing into another domain. The record scores it with a scope change and high impact across the board, at high attack complexity since it requires driving the allocator to exhaustion.
Who can reach it
Local, low-privileged, on an AMD host using nested IOMMU domains for passthrough. The attacker needs enough control to exhaust the domain ID space or induce allocation failure while a nested domain is created - not a single-syscall trigger.
What to do
Install a kernel carrying the iommu/amd fix and reboot the affected AMD hosts; IOMMU domain setup happens in the boot and device-attach paths, so there is no live fix. Only hosts doing AMD passthrough/nested-domain virtualization need the window.
References
Related entries
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.