Junglewise Threat Intelligence

CVE-2026-43220: Linux Kernel AMD IOMMU race condition in TLB invalidation

CVE-2026-43220 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AMD IOMMU driver can cause system instability or timeouts during memory management operations. The IOMMU is a critical component that manages how hardware devices interact with system memory; when it fails to process commands in the correct order, it can lead to random system hangs or performance issues. This issue primarily affects systems using AMD processors with virtualization or advanced memory protection features enabled.

Technical details

A race condition exists in the Linux kernel's AMD IOMMU driver (drivers/iommu/amd/) due to improper serialization of command sequence numbers. Specifically, the 'cmd_sem_val' was being incremented outside of the IOMMU spinlock during concurrent Translation Lookaside Buffer (TLB) invalidations. This allowed 'CMD_COMPL_WAIT' commands to be queued out of sequence, violating the ordering assumptions required by 'wait_on_sem()' and resulting in random completion timeouts. An attacker with local access could potentially trigger this condition to cause a kernel-level denial of service. The fix involves moving the sequence increment inside the 'iommu->lock' critical section to ensure atomic serialization with command queuing.

Affected products

  • Linux Linux Kernel 6.12.75 to 6.13, 6.6.128 to 6.7

Timeline

  • 2026-05-06: disclosed: Initial CVE publication
  • 2026-02-03: patched: Upstream patch committed to mainline kernel
  • 2026-05-06: advisory: NVD advisory published

References

Related threats