8.8
CVE-2026-74520
- EPSS 0.13%
- Veröffentlicht 15.08.2026 12:27:38
- Zuletzt bearbeitet 17.08.2026 06:19:48
- CVE-Watchlists
- Unerledigt
iommu/iommufd: Fix IOPF group ownership UAF
In the Linux kernel, the following vulnerability has been resolved: iommu/iommufd: Fix IOPF group ownership UAF iopf_group_alloc() links each last-page IOPF group into the generic IOPF pending list before invoking the domain fault handler. iommufd_fault_iopf_handler() also queued an accepted group in the IOMMUFD deliver list without removing it from the generic pending list. When detach or HWPT replacement drops the device's IOPF reference count to zero, an IOMMU driver may call iopf_queue_remove_device(). That function responds to and frees groups through the generic pending list without removing the same groups from IOMMUFD's deliver list or response xarray. A later read, response, or cleanup can then access the freed group and cause a UAF. Fix this by dequeuing an accepted group from the generic pending list before IOMMUFD queues it for userspace response. Make iopf_group_response() send a response regardless of pending-list membership, so the dequeued group can still be completed by IOMMUFD.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
34765cbc679c59ea5d952d738d2d16bf4aadc497
Version <
6da8f37419dd4c456f26fc203f04e000186f4b3d
Status
affected
Version
34765cbc679c59ea5d952d738d2d16bf4aadc497
Version <
4e74a369236424114b94cf6a9f5ff9e848b430b4
Status
affected
Version
34765cbc679c59ea5d952d738d2d16bf4aadc497
Version <
738e6f32e61d80b554e37015ecb7bc620b88001c
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.11
Status
affected
Version
0
Version <
6.11
Status
unaffected
Version <=
6.18.*
Version
6.18.44
Status
unaffected
Version <=
7.1.*
Version
7.1.8
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.028 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/6da8f37419dd4c456f26fc203f04e000186f4b3d
https://git.kernel.org/stable/c/4e74a369236424114b94cf6a9f5ff9e848b430b4
https://git.kernel.org/stable/c/738e6f32e61d80b554e37015ecb7bc620b88001c