8.8

CVE-2026-89445

iommufd: Fix UAF in selftest IOPF reporting

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Fix UAF in selftest IOPF reporting

IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from
group->pasid_array without synchronizing against PASID detach,
then a concurrent iommu_report_device_fault() can dereference
that borrowed handle's domain pointer after the detach erases
the handle and frees the backing struct iommufd_attach_handle.
TRIGGER_IOPF then dereferences the freed handle, causing a UAF.

Fix by adding a iopf_rwsem in mock_dev to follow the expected design
of a real driver. Hold its read side across the whole
iommu_report_device_fault() call, and its write side around every
path that attaches, detaches, or replaces a device domain.
This can block new reports and drains in-flight reports before an old
attach handle or the IOPF fault parameter can be removed.
Also take the write side while registering a mock device, since
it can invoke the mock driver's default-domain attach callback.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ddee19971081b42615d62f4fdada21274708ed4d
Version < fd2e7ac94d6d813548b021473c3dddc30c8c07d1
Status affected
Version ddee19971081b42615d62f4fdada21274708ed4d
Version < cab2895729516799384d48560e6fca105fb3f927
Status affected
Version ddee19971081b42615d62f4fdada21274708ed4d
Version < e27e90bde68b2ab92e63ed19caad1ef57188bea0
Status affected
Version ddee19971081b42615d62f4fdada21274708ed4d
Version < 8c07df7cdfcf52f1ff276c588612aabc6c6b8399
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cab2895729516799384d48560e6fca105fb3f927
https://git.kernel.org/stable/c/e27e90bde68b2ab92e63ed19caad1ef57188bea0
https://git.kernel.org/stable/c/8c07df7cdfcf52f1ff276c588612aabc6c6b8399
https://git.kernel.org/stable/c/fd2e7ac94d6d813548b021473c3dddc30c8c07d1