Junglewise Threat Intelligence

CVE-2026-43161: Linux Kernel hard-lock in Intel IOMMU VT-d during PCIe device removal

CVE-2026-43161 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's handling of certain hardware components (PCIe devices) can cause the entire host system to freeze or 'hard-lock'. This occurs when a high-performance hardware device, such as a network card assigned to a virtual machine, loses its connection or is removed unexpectedly. An attacker with local access or a malfunctioning virtual machine could trigger this condition, leading to a complete service outage of the physical server.

Technical details

A flaw exists in the Intel IOMMU (VT-d) driver where the kernel may enter an infinite wait state during a dev-iotlb flush. When PCIe endpoints with ATS enabled are passed through to userspace (via VFIO/QEMU/DPDK) and experience a surprise removal or link fault, the `qi_submit_sync` function waits indefinitely for an ATS invalidation completion that never arrives because the device is inaccessible. This specifically affects systems where Intel IOMMU scalable mode is disabled or unsupported. The fix introduces a check using `pci_device_is_present()` within `__context_flush_dev_iotlb()` to skip flushes for disconnected devices. Patches have been backported to various stable kernel branches including 6.12.y, 6.18.y, and 6.19.y.

Affected products

  • Linux Linux Kernel 5.12.19 to 5.13, 5.13.4 to 5.14, 5.14.1 to 6.12.77, 6.13 to 6.18.17, 6.19 to 6.19.6

Timeline

  • 2026-01-22: patched: Initial fix committed to mainline kernel
  • 2026-05-06: disclosed: CVE-2026-43161 assigned and published

References

Related threats