Executive brief
A vulnerability was identified in the Linux kernel's memory management system on x86 systems. The issue involves how the system handles internal memory address translations (IOTLB) when kernel memory is freed and reused. An unprivileged user could potentially exploit this to access or modify sensitive kernel data, leading to a full system compromise or data theft.
Technical details
The vulnerability stems from a failure to invalidate stale IOTLB (Input/Output Translation Lookaside Buffer) paging cache entries for the kernel address space on x86 architectures using Shared Virtual Addressing (SVA). Specifically, when kernel page table pages are freed (e.g., during vfree() operations), the IOMMU was not notified to flush the corresponding paging cache entries before the memory was reused. This creates a race condition or stale mapping scenario where an attacker with local unprivileged access could potentially leverage these stale entries to access kernel memory. The fix introduces a new IOMMU interface, iommu_sva_invalidate_kva_range(), to ensure proper invalidation during page table teardown. The issue is addressed in kernel versions 6.18.7 and 6.19.
Affected products
- Linux Linux Kernel 4.4 to 6.18.7
Timeline
- 2025-02-14: disclosed
- 2026-01-23: patched: Commit 9f0a7ab700f8620e433b05c57fbd26c92ea186d9