Junglewise Threat Intelligence

CVE-2026-45894: Linux Kernel race condition in Intel VT-d PASID teardown

CVE-2026-45894 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's handling of Intel VT-d virtualization technology. The system's memory management component could occasionally read inconsistent data when a virtual machine's access rights were being removed. This could lead to unpredictable system behavior or unexpected errors, potentially impacting the stability of servers running virtualized workloads.

Technical details

A race condition exists in the iommu/vt-d driver when tearing down Scalable Mode PASID table entries. The Intel VT-d PASID entry is 64 bytes, but the kernel was zeroing the structure using multiple 64-bit writes while the 'Present' (P) bit was still set. Because the IOMMU hardware may fetch these 64 bytes using multiple internal transactions, it could observe an inconsistent or 'torn' state if a fetch occurred simultaneously with the CPU's zeroing operation. This violates the VT-d specification's guidance for invalidations. The fix implements a proper ownership handshake: clearing the Present bit first, issuing a memory barrier (dma_wmb), performing the required cache/TLB flushes, and only then zeroing the remaining fields.

Affected products

  • Linux Linux Kernel Fixed in versions 75ed000, 821807c, 949d716, a84d30e

Timeline

  • 2026-01-22: patched: Initial patch authored by Intel
  • 2026-05-27: disclosed: CVE published to NVD dataset

References

Related threats