GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux AMD IOMMU: sign-discarding error check lets nested domains use an unallocated domain ID

CVSS 7.8CVE-2026-98002Kernel, userspace & hypervisorcurated

Impact

amd_iommu_alloc_domain_nested() stores the int return of amd_iommu_pdom_id_alloc() into a u32 before testing it, so a negative errno becomes a large positive value and the failure check never fires. Under ID-space exhaustion or memory pressure the nested IOMMU domain is set up with a host domain ID that was never allocated, instead of failing with -ENOSPC. Nested IOMMU domains are what back device passthrough to guests, so on an AMD GPU virtualization host this means a passthrough domain sharing or colliding with an ID that belongs elsewhere - the isolation boundary that keeps a tenant's passed-through GPU or NIC from DMAing into another domain. The record scores it with a scope change and high impact across the board, at high attack complexity since it requires driving the allocator to exhaustion.

Who can reach it

Local, low-privileged, on an AMD host using nested IOMMU domains for passthrough. The attacker needs enough control to exhaust the domain ID space or induce allocation failure while a nested domain is created - not a single-syscall trigger.

What to do

Install a kernel carrying the iommu/amd fix and reboot the affected AMD hosts; IOMMU domain setup happens in the boot and device-attach paths, so there is no live fix. Only hosts doing AMD passthrough/nested-domain virtualization need the window.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.