8.2

CVE-2026-90241

iommu/vt-d: Tear down scalable-mode context on probe failure

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Tear down scalable-mode context on probe failure

intel_pasid_setup_sm_context() walks a PCI device’s DMA aliases via
pci_for_each_dma_alias() and programs a scalable-mode context entry for
each RID. For a device with a dma_alias_mask, the callback is invoked
once for the device’s own RID and once for each alias bit, all with the
same pci_dev, so device_pasid_table_setup() runs for multiple RIDs.

pci_for_each_dma_alias() stops at the first callback error. Therefore, a
failure partway through the walk can leave context entries for already
processed RIDs present and still pointing to the device’s PASID table.

On this error path, intel_iommu_probe_device() currently jumps directly
to intel_pasid_free_table(), which frees the PASID table without
first tearing down those context entries. The IOMMU may then walk a
present context entry whose PASID table pointer references freed
memory.

intel_iommu_release_device() already performs teardown before freeing the
table. Apply the same ordering on the probe failure path.

device_pasid_table_teardown() safely handles RIDs that were never
programmed: iommu_context_addr() returns NULL when no context table has
been allocated, and clearing the Present bit of an already non-present
entry is a no-op. So unwind is safe for both the alias that failed and
any aliases not yet reached.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 301f1a80487fd2f51012533792583d4425e8b8c0
Version < 25ac85a9747cd63e1d166ace7b360a2cd9479d9d
Status affected
Version 301f1a80487fd2f51012533792583d4425e8b8c0
Version < d0e978ced7429b516358bb4d41d337214768ae98
Status affected
Version 301f1a80487fd2f51012533792583d4425e8b8c0
Version < db5daf25f754cdc20c18525adb88240ece6fdee9
Status affected
Version 301f1a80487fd2f51012533792583d4425e8b8c0
Version < c509fb73a1093a15accd7d43a61645d4b520f6ac
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.068
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/25ac85a9747cd63e1d166ace7b360a2cd9479d9d
https://git.kernel.org/stable/c/d0e978ced7429b516358bb4d41d337214768ae98
https://git.kernel.org/stable/c/db5daf25f754cdc20c18525adb88240ece6fdee9
https://git.kernel.org/stable/c/c509fb73a1093a15accd7d43a61645d4b520f6ac