Executive brief
The Linux kernel's iommufd subsystem (used for managing IOMMU device access) contains a race condition in the IOMMUFD_DESTROY command that can lead to refcount synchronization violations. An attacker with access to iommufd operations could exploit this to cause denial of service or potentially gain unauthorized device access by racing destroy operations with other concurrent operations.
Technical details
The vulnerability is a race condition in the iommufd subsystem where the IOMMUFD_DESTROY command improperly increments the refcount without holding the destroy_rwsem lock, violating the invariant that all temporary refcount elevations must be protected by destroy_rwsem. The affected code path calls iommufd_get_object(), then iommufd_ref_to_users(), allowing concurrent access to race with iommufd_object_destroy_user(). This causes spurious failures and warnings in access destruction. The fix serializes refcount validation and object erasure under the xa_lock critical section instead of incrementing refcounts, with the tradeoff that racing userspace operations receive EBUSY errors rather than waiting. The vulnerability requires local access to iommufd operations and can be triggered through ioctl syscalls.
Affected products
- Linux Linux kernel affected versions prior to fix (exact version range not specified in advisory)
Timeline
- 2025-12-09: disclosed