Executive brief
A vulnerability was identified in the Linux kernel's Intel IOMMU driver, which manages how hardware devices interact with system memory. When a device is disconnected from a specific memory management feature (SVA), the system may incorrectly clean up resources while they are still in use. This can lead to a system crash (kernel panic), potentially disrupting operations or allowing a local user to destabilize the system.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's VT-d driver (drivers/iommu/intel/iommu.c). The root cause is an incorrect ordering of operations in the 'blocking_domain_set_dev_pasid' function, where 'iopf_for_domain_remove()' was called before 'intel_pasid_tear_down_entry()'. This allowed the system to remove a device from the IOMMU's IOPF queue while page faults were still in flight or being generated by hardware. An attacker with local access could trigger this race condition during SVA unbind, leading to a refcount underflow and kernel panic. The fix involves reordering the calls to ensure hardware is blocked from generating new faults and in-flight faults are flushed before the domain is removed.
Affected products
- Linux Linux Kernel 6.16, 6.17, and versions starting from commit 17fce9d2336d before fix
Timeline
- 2025-07-23: patched: Fix proposed and signed off by maintainers
- 2025-08-19: disclosed: CVE-2025-38594 published