-

CVE-2026-80687

iommufd/viommu: Release the igroup lock on the vdevice_size error path

In the Linux kernel, the following vulnerability has been resolved:

iommufd/viommu: Release the igroup lock on the vdevice_size error path

iommufd_vdevice_alloc_ioctl() takes idev->igroup->lock, then validates the
driver's vdevice_size against the core structure size with a WARN_ON_ONCE.
On failure that guard jumps to out_put_idev, below out_unlock_igroup, so it
skips the mutex_unlock(), leaving the igroup lock held and deadlocking the
next vDEVICE operation on that group.

Jump to out_unlock_igroup instead.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ed42eee797ff3dc889ade63c1dd7c4f430699e23
Version < 294b464b2be7e57872864cb6936e1d9c7294f89d
Status affected
Version ed42eee797ff3dc889ade63c1dd7c4f430699e23
Version < ca9e49e1c8931a4e6e743a1f1d2e7f977f774b86
Status affected
Version ed42eee797ff3dc889ade63c1dd7c4f430699e23
Version < 339bd11591593ab7ce88136ab7fd01ef3813b724
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.17
Status affected
Version 0
Version < 6.17
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/294b464b2be7e57872864cb6936e1d9c7294f89d
https://git.kernel.org/stable/c/ca9e49e1c8931a4e6e743a1f1d2e7f977f774b86
https://git.kernel.org/stable/c/339bd11591593ab7ce88136ab7fd01ef3813b724